CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,899 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
150,374 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-10079 EXP | SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515. | Patch early | 7.5 high | 6.5% | 2017-02-01 |
| CVE-2012-6653 EXP | Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors. | Patch early | 7.5 high | 6.5% | 2014-08-06 |
| CVE-2018-10577 EXP | An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.… | Patch early | 8.8 high | 6.5% | 2018-05-02 |
| CVE-2018-4386 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1… | Patch early | 8.8 high | 6.5% | 2019-04-03 |
| CVE-2011-3336 EXP | regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion. | Patch early | 7.5 high | 6.5% | 2020-02-12 |
| CVE-2004-2677 EXP | Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format… | Patch early | 7.5 high | 6.5% | 2004-12-31 |
| CVE-2011-5166 EXP | Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string to the (1) USER, (2) PASS, (3)… | Patch early | 7.5 high | 6.5% | 2012-09-15 |
| CVE-2017-2476 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 6.5% | 2017-04-02 |
| CVE-2015-0569 EXP | Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux ker… | Patch early | 7.8 high | 6.5% | 2016-05-09 |
| CVE-2003-0755 EXP | Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and list… | Patch early | 10.0 high | 6.5% | 2003-10-20 |
| CVE-2002-0968 EXP | Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long… | Patch early | 7.5 high | 6.5% | 2002-10-04 |
| CVE-2007-2791 EXP | Unspecified vulnerability in the Secure Shell (SSH) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows remote attackers to identify valid users via unspecified… | Patch early | 10.0 high | 6.5% | 2007-05-22 |
| CVE-2008-3167 EXP | Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitr… | Patch early | 9.3 high | 6.5% | 2008-07-14 |
| CVE-2006-4848 EXP | Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the RE… | Patch early | 7.5 high | 6.5% | 2006-09-19 |
| CVE-2009-3318 EXP | Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary dir… | Patch early | 7.5 high | 6.5% | 2009-09-23 |
| CVE-2006-3015 EXP | Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double… | Patch early | 7.1 high | 6.5% | 2006-06-14 |
| CVE-2019-12137 EXP | Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note. | Patch early | 7.8 high | 6.5% | 2019-05-16 |
| CVE-2018-4366 EXP | A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1. | Patch early | 7.5 high | 6.4% | 2019-04-03 |
| CVE-2018-9106 EXP | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via… | Patch early | 8.8 high | 6.4% | 2018-03-28 |
| CVE-2017-5227 EXP | QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format… | Patch early | 7.5 high | 6.4% | 2017-03-23 |
| CVE-2020-27423 EXP | Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legiti… | Patch early | 7.5 high | 6.4% | 2020-11-16 |
| CVE-2009-4987 EXP | admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting… | Patch early | 7.5 high | 6.4% | 2010-08-25 |
| CVE-2011-4042 EXP | An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute ar… | Patch early | 9.3 high | 6.4% | 2012-04-03 |
| CVE-2009-3717 EXP | Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long U… | Patch early | 9.3 high | 6.4% | 2009-10-16 |
| CVE-2007-2827 EXP | Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute… | Patch early | 9.3 high | 6.4% | 2007-05-22 |
| CVE-2007-2981 EXP | Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e.dll) 14.5.0.44 allows remote… | Patch early | 9.3 high | 6.4% | 2007-06-01 |
| CVE-2000-0848 EXP | Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header. | Patch early | 10.0 high | 6.4% | 2000-11-14 |
| CVE-2018-13110 EXP | All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerability where attackers can gain acc… | Patch early | 7.5 high | 6.4% | 2018-07-06 |
| CVE-2008-7161 EXP | Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via fragmented GET or POST reques… | Patch early | 7.5 high | 6.4% | 2009-09-04 |
| CVE-2003-0371 EXP | Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a l… | Patch early | 7.5 high | 6.4% | 2003-06-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt