CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
150,376 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-2824 EXP | Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL co… | Patch early | 7.5 high | 6.2% | 2015-04-06 |
| CVE-2009-3838 EXP | Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash)… | Patch early | 9.3 high | 6.2% | 2009-11-02 |
| CVE-2020-20969 EXP | File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file. | Patch early | 7.2 high | 6.2% | 2023-06-20 |
| CVE-2004-1303 EXP | Buffer overflow in the get function in get.c for Yanf 0.4 allows remote malicious web servers to execute arbitrary code via crafted HTTP responses. | Patch early | 10.0 high | 6.2% | 2005-01-10 |
| CVE-2009-0422 EXP | Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers… | Patch early | 7.5 high | 6.2% | 2009-02-05 |
| CVE-2007-6273 EXP | Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote attac… | Patch early | 9.3 high | 6.2% | 2007-12-07 |
| CVE-2002-0942 EXP | Buffer overflows in Lugiment Log Explorer before 3.02 allow attackers with database permissions to execute arbitrary code via long arguments to the ex… | Patch early | 7.5 high | 6.2% | 2002-10-04 |
| CVE-2007-0466 EXP | Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Propertie… | Patch early | 10.0 high | 6.2% | 2007-01-31 |
| CVE-2024-24409 EXP | Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option. | Patch early | 8.8 high | 6.2% | 2024-11-08 |
| CVE-2009-0262 EXP | Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string… | Patch early | 9.3 high | 6.2% | 2009-01-23 |
| CVE-2018-10018 EXP | The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a long IsBlackListed argument. | Patch early | 8.8 high | 6.2% | 2018-07-13 |
| CVE-2006-7032 EXP | PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to execute arbitrary code via a URL i… | Patch early | 10.0 high | 6.2% | 2007-02-23 |
| CVE-2009-2568 EXP | Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary code via a long string in a play… | Patch early | 9.3 high | 6.2% | 2009-07-22 |
| CVE-2022-47076 EXP | An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via DisplayParallelLogData.aspx. | Patch early | 7.5 high | 6.2% | 2023-02-28 |
| CVE-2009-1743 EXP | Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows… | Patch early | 9.3 high | 6.2% | 2009-05-21 |
| CVE-2000-0828 EXP | Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agen… | Patch early | 10.0 high | 6.2% | 2000-11-14 |
| CVE-1999-0287 EXP | Vulnerability in the Wguest CGI program. | Patch early | 7.5 high | 6.2% | 1999-04-09 |
| CVE-2004-1301 EXP | Buffer overflow in the book_format_sql function in format.c for xlreader 0.9.0 allows remote attackers to execute arbitrary code via a crafted Excel (… | Patch early | 10.0 high | 6.2% | 2005-01-10 |
| CVE-2006-3491 EXP | Stack-based buffer overflow in Kaillera Server 0.86 and earlier allows remote attackers to execute arbitrary code via a long nickname. | Patch early | 7.5 high | 6.2% | 2006-07-10 |
| CVE-2007-2474 EXP | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 6.2% | 2007-05-02 |
| CVE-2009-1368 EXP | Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parame… | Patch early | 7.5 high | 6.2% | 2009-04-22 |
| CVE-2004-0290 EXP | Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1… | Patch early | 10.0 high | 6.1% | 2004-11-23 |
| CVE-2005-2367 EXP | Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11, as used in multiple dissectors, allows remote attac… | Patch early | 7.5 high | 6.1% | 2005-08-10 |
| CVE-2016-3219 EXP | The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of… | Patch early | 7.8 high | 6.1% | 2016-06-16 |
| CVE-2018-7466 EXP | install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES dat… | Patch early | 7.5 high | 6.1% | 2018-02-25 |
| CVE-2007-3167 EXP | Stack-based buffer overflow in the Vivotek Motion Jpeg ActiveX control (aka MjpegControl) in MjpegDecoder.dll 2.0.0.13 allows remote attackers to exec… | Patch early | 7.6 high | 6.1% | 2007-06-11 |
| CVE-2007-2761 EXP | Stack-based buffer overflow in MagicISO 5.4 build 239 and earlier allows remote attackers to execute arbitrary code via a long filename in a .cue file… | Patch early | 7.5 high | 6.1% | 2007-05-18 |
| CVE-2009-3306 EXP | PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 6.1% | 2009-09-23 |
| CVE-2008-6143 EXP | OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie. | Patch early | 7.5 high | 6.1% | 2009-02-16 |
| CVE-1999-0238 EXP | php.cgi allows attackers to read any file on the system. | Patch early | 10.0 high | 6.1% | 1997-08-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt