CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,553 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
320,595 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-1090 EXP | Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title. | Patch early | 10.0 high | 11.6% | 2003-02-06 |
| CVE-2009-3859 EXP | Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cau… | Patch early | 9.3 high | 11.6% | 2009-11-04 |
| CVE-2002-0591 EXP | Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute co… | Patch early | 5.0 medium | 11.6% | 2002-06-18 |
| CVE-2009-1574 EXP | racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a… | Patch early | 5.0 medium | 11.6% | 2009-05-06 |
| CVE-2008-4116 EXP | Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbit… | Patch early | 9.3 high | 11.6% | 2008-09-18 |
| CVE-2019-19731 EXP | Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE acti… | Patch early | 7.5 high | 11.6% | 2019-12-16 |
| CVE-2003-0129 EXP | Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that i… | Patch early | 5.0 medium | 11.6% | 2003-03-24 |
| CVE-2011-4189 EXP | The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corrup… | Patch early | 7.5 high | 11.6% | 2012-03-02 |
| CVE-2019-8925 EXP | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zon… | Patch early | 4.3 medium | 11.6% | 2019-05-17 |
| CVE-1999-0710 EXP | The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attacker… | Patch early | 7.5 high | 11.6% | 1999-07-25 |
| CVE-2002-1456 EXP | Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value. | Patch early | 7.5 high | 11.6% | 2003-06-09 |
| CVE-2004-1147 EXP | phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands vi… | Patch early | 10.0 high | 11.6% | 2005-01-10 |
| CVE-2007-2209 EXP | Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products… | Patch early | 6.8 medium | 11.6% | 2007-04-24 |
| CVE-2007-0233 EXP | wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matchi… | Patch early | 7.5 high | 11.6% | 2007-01-13 |
| CVE-2014-9014 EXP | Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allo… | Patch early | 4.3 medium | 11.6% | 2019-11-06 |
| CVE-2022-22833 EXP | An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request. | Patch early | 7.5 high | 11.6% | 2022-02-06 |
| CVE-2015-4181 EXP | Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot)… | Patch early | 7.5 high | 11.6% | 2017-08-25 |
| CVE-2012-1125 EXP | Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 for WordPress allows remote atta… | Patch early | 6.8 medium | 11.6% | 2012-10-08 |
| CVE-2008-7257 EXP | CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1… | Patch early | 4.3 medium | 11.6% | 2010-06-29 |
| CVE-2003-0263 EXP | Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FRO… | Patch early | 7.5 high | 11.6% | 2003-05-27 |
| CVE-2013-7186 EXP | Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long string in a .m3u file. | Patch early | 9.3 high | 11.6% | 2013-12-20 |
| CVE-2013-2261 EXP | Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure | Patch early | 7.5 high | 11.6% | 2019-11-04 |
| CVE-2007-4254 EXP | Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Designer 7.0 for Microsoft Visual St… | Patch early | 6.8 medium | 11.5% | 2007-08-08 |
| CVE-2018-10517 EXP | In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploit… | Patch early | 7.2 high | 11.5% | 2018-04-27 |
| CVE-2008-0944 EXP | Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via… | Patch early | 5.0 medium | 11.5% | 2008-02-25 |
| CVE-2019-6273 EXP | download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files. | Patch early | 6.5 medium | 11.5% | 2019-03-21 |
| CVE-1999-0284 EXP | Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. | Patch early | 7.5 high | 11.5% | 1998-01-01 |
| CVE-2010-0397 EXP | The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, w… | Patch early | 5.0 medium | 11.5% | 2010-03-16 |
| CVE-2009-0544 EXP | Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large… | Patch early | 10.0 high | 11.5% | 2009-02-12 |
| CVE-2008-1289 EXP | Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x b… | Patch early | 7.5 high | 11.5% | 2008-03-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt