CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,984 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
150,377 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-2521 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. wa… | Patch early | 8.8 high | 5.9% | 2017-05-22 |
| CVE-2009-3709 EXP | Stack-based buffer overflow in the Meta Content Optimizer in Konae Technologies Alleycode HTML Editor 2.21 allows user-assisted remote attackers to ex… | Patch early | 9.3 high | 5.9% | 2009-10-16 |
| CVE-2000-0384 EXP | NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC add… | Patch early | 10.0 high | 5.9% | 2000-05-08 |
| CVE-2000-0300 EXP | The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accou… | Patch early | 10.0 high | 5.9% | 2000-04-06 |
| CVE-2007-6555 EXP | PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote at… | Patch early | 9.3 high | 5.9% | 2007-12-28 |
| CVE-2018-6388 EXP | iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in t… | Patch early | 8.8 high | 5.9% | 2018-01-29 |
| CVE-2010-2127 EXP | PHP remote file inclusion vulnerability in gallery.php in JV2 Folder Gallery 3.1 allows remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 7.5 high | 5.9% | 2010-06-01 |
| CVE-2010-2137 EXP | PHP remote file inclusion vulnerability in _center.php in ProMan 0.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 5.9% | 2010-06-02 |
| CVE-2014-0358 EXP | Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via a .. (dot do… | Patch early | 7.8 high | 5.9% | 2014-04-15 |
| CVE-2004-2375 EXP | Buffer overflow in the POP3 server in 1st Class Mail Server 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbi… | Patch early | 7.5 high | 5.9% | 2004-12-31 |
| CVE-2008-5755 EXP | Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows remote attackers to execute arbitrary code via a MAP file containing a long URL, pos… | Patch early | 9.3 high | 5.9% | 2008-12-30 |
| CVE-2002-2379 EXP | Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of service… | Patch early | 7.8 high | 5.9% | 2002-12-31 |
| CVE-2006-6055 EXP | Stack-based buffer overflow in A5AGU.SYS 1.0.1.41 for the D-Link DWL-G132 wireless adapter allows remote attackers to execute arbitrary code via a 802… | Patch early | 10.0 high | 5.9% | 2006-11-22 |
| CVE-2009-3536 EXP | Multiple stack-based buffer overflows in EpicDJSoftware EpicVJ 1.2.8.0 and 1.3.1.2 allow remote attackers to cause a denial of service (application cr… | Patch early | 9.3 high | 5.9% | 2009-10-02 |
| CVE-2009-0349 EXP | Stack-based buffer overflow in FTPShell Server 4.3 allows user-assisted remote attackers to cause a denial of service (persistent daemon crash) and po… | Patch early | 9.3 high | 5.9% | 2009-01-29 |
| CVE-2009-0491 EXP | Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary code via a M3U file containing… | Patch early | 9.3 high | 5.9% | 2009-02-10 |
| CVE-2009-1449 EXP | Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attackers to execute arbitrary code vi… | Patch early | 9.3 high | 5.9% | 2009-04-27 |
| CVE-2009-2384 EXP | Buffer overflow in amp.exe in Brothersoft PEamp 1.02b allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u play… | Patch early | 9.3 high | 5.9% | 2009-07-08 |
| CVE-2000-0437 EXP | Buffer overflow in the CyberPatrol daemon "cyberdaemon" used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute… | Patch early | 10.0 high | 5.9% | 2000-05-18 |
| CVE-2000-0584 EXP | Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name… | Patch early | 10.0 high | 5.9% | 2000-07-02 |
| CVE-2000-0706 EXP | Buffer overflows in ntop running in web mode allows remote attackers to execute arbitrary commands. | Patch early | 10.0 high | 5.9% | 2000-10-20 |
| CVE-2003-0509 EXP | SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via t… | Patch early | 10.0 high | 5.9% | 2003-08-07 |
| CVE-2006-1232 EXP | Multiple SQL injection vulnerabilities in DSDownload 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 5.9% | 2006-03-14 |
| CVE-2007-1398 EXP | The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, allo… | Patch early | 7.1 high | 5.9% | 2007-03-10 |
| CVE-2009-1329 EXP | Stack-based buffer overflow in Mini-stream Shadow Stream Recorder 3.0.1.7 allows remote attackers to execute arbitrary code via a long URI in a playli… | Patch early | 9.3 high | 5.8% | 2009-04-17 |
| CVE-2009-1815 EXP | Stack-based buffer overflow in Sonic Spot Audioactive Player 1.93b allows remote attackers to execute arbitrary code via a long string in a playlist f… | Patch early | 9.3 high | 5.8% | 2009-05-29 |
| CVE-2010-2146 EXP | PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP code via a URL in the VL_incl… | Patch early | 7.5 high | 5.8% | 2010-06-03 |
| CVE-1999-0455 EXP | The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does n… | Patch early | 7.5 high | 5.8% | 1999-12-25 |
| CVE-2007-3071 EXP | Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted… | Patch early | 9.3 high | 5.8% | 2007-06-06 |
| CVE-2011-4334 EXP | edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP file… | Patch early | 8.8 high | 5.8% | 2017-10-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt