CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,585 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
187,055 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-12706 EXP | DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header. | Patch early | 9.8 critical | 9.9% | 2018-06-24 |
| CVE-2001-1287 EXP | Buffer overflow in Web Calendar in Ipswitch IMail 7.04 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | Patch early | 7.5 high | 9.9% | 2001-10-12 |
| CVE-2005-0689 EXP | includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template paramet… | Patch early | 7.5 high | 9.9% | 2005-03-07 |
| CVE-2002-1057 EXP | Buffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a long USER command. | Patch early | 7.5 high | 9.9% | 2002-10-04 |
| CVE-2005-0226 EXP | Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with… | Patch early | 7.5 high | 9.9% | 2005-02-03 |
| CVE-2019-11705 EXP | A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resu… | Patch early | 9.8 critical | 9.9% | 2019-07-23 |
| CVE-2004-1666 EXP | Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a newline chara… | Patch early | 7.5 high | 9.9% | 2004-12-31 |
| CVE-2006-4870 EXP | Multiple PHP remote file inclusion vulnerabilities in AEDating 4.1, and possibly earlier versions, allow remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 9.9% | 2006-09-19 |
| CVE-2018-20159 EXP | i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with t… | Patch early | 7.2 high | 9.9% | 2018-12-15 |
| CVE-2000-0012 EXP | Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands. | Patch early | 10.0 high | 9.9% | 1999-12-27 |
| CVE-2013-6231 EXP | SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script | Patch early | 8.8 high | 9.9% | 2020-01-10 |
| CVE-2022-23626 EXP | m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` have not been checked properly… | Patch early | 8.5 high | 9.9% | 2022-02-08 |
| CVE-2004-2347 EXP | blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metacharacters such as '|' in the fi… | Patch early | 7.5 high | 9.9% | 2004-12-31 |
| CVE-2004-0613 EXP | osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to t… | Patch early | 7.5 high | 9.9% | 2004-12-06 |
| CVE-2005-0523 EXP | Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Loca… | Patch early | 7.5 high | 9.9% | 2005-05-02 |
| CVE-2006-4196 EXP | PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 9.9% | 2006-08-17 |
| CVE-2006-2744 EXP | PHP remote file inclusion vulnerability in p-popupgallery.php in F@cile Interactive Web 0.8.41 through 0.8.5 allows remote attackers to execute arbitr… | Patch early | 7.5 high | 9.9% | 2006-06-01 |
| CVE-2007-2424 EXP | PHP remote file inclusion vulnerability in help/index.php in The Merchant (themerchant) 2.2 allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 9.9% | 2007-05-02 |
| CVE-1999-1588 EXP | Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string begi… | Patch early | 9.8 critical | 9.9% | 1999-12-31 |
| CVE-2012-4988 EXP | Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to… | Patch early | 9.3 high | 9.9% | 2014-07-09 |
| CVE-2019-11374 EXP | 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI. | Patch early | 8.8 high | 9.9% | 2019-04-20 |
| CVE-2008-5120 EXP | Stack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbitr… | Patch early | 10.0 high | 9.9% | 2008-11-18 |
| CVE-2018-6220 EXP | An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to… | Patch early | 9.8 critical | 9.9% | 2018-03-15 |
| CVE-2009-4623 EXP | Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 7.5 high | 9.8% | 2010-01-18 |
| CVE-2001-1343 EXP | ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the k… | Patch early | 7.5 high | 9.8% | 2001-06-12 |
| CVE-2023-27100 EXP | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software… | Patch early | 9.8 critical | 9.8% | 2023-03-22 |
| CVE-2016-5399 EXP | The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of serv… | Patch early | 7.8 high | 9.8% | 2017-04-21 |
| CVE-2019-16294 EXP | SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file… | Patch early | 7.8 high | 9.8% | 2019-09-14 |
| CVE-2010-0071 EXP | Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to… | Patch early | 10.0 high | 9.8% | 2010-01-13 |
| CVE-2017-17417 EXP | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is… | Patch early | 9.8 critical | 9.8% | 2018-02-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt