CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,984 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
150,377 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-17525 EXP | The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks. | Patch early | 8.8 high | 5.8% | 2020-04-21 |
| CVE-2007-1412 EXP | The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source… | Patch early | 7.8 high | 5.8% | 2007-03-12 |
| CVE-2017-6088 EXP | Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands v… | Patch early | 7.2 high | 5.8% | 2017-04-11 |
| CVE-2018-6323 EXP | The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigne… | Patch early | 7.8 high | 5.8% | 2018-01-26 |
| CVE-2010-4884 EXP | PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 7.5 high | 5.8% | 2011-10-07 |
| CVE-2002-1951 EXP | Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirec… | Patch early | 7.5 high | 5.8% | 2002-12-31 |
| CVE-2010-4170 EXP | The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileg… | Patch early | 7.2 high | 5.8% | 2010-12-07 |
| CVE-2017-2362 EXP | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. Th… | Patch early | 8.8 high | 5.8% | 2017-02-20 |
| CVE-2018-4382 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1… | Patch early | 8.8 high | 5.8% | 2019-04-03 |
| CVE-2018-4438 EXP | A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.… | Patch early | 8.8 high | 5.8% | 2019-04-03 |
| CVE-2018-4442 EXP | A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, S… | Patch early | 8.8 high | 5.8% | 2019-04-03 |
| CVE-2018-4443 EXP | A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, S… | Patch early | 8.8 high | 5.8% | 2019-04-03 |
| CVE-2004-1793 EXP | Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code via a long m… | Patch early | 7.5 high | 5.8% | 2004-12-31 |
| CVE-2007-1501 EXP | Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary… | Patch early | 9.3 high | 5.8% | 2007-03-19 |
| CVE-2009-1660 EXP | Stack-based buffer overflow in URUWorks ViPlay3 3.0 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbi… | Patch early | 9.3 high | 5.8% | 2009-05-18 |
| CVE-2010-2315 EXP | PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 5.8% | 2010-06-17 |
| CVE-2005-3485 EXP | Buffer overflow in Glider Collect'n kill 1.0.0.0 allows remote attackers to execute arbitrary code via a gl_playerEnter command with a long player nam… | Patch early | 7.5 high | 5.8% | 2005-11-03 |
| CVE-2005-2639 EXP | Buffer overflow in Chris Moneymaker's World Poker Championship 1.0 allows remote attackers to cause a denial of service (application crash) and possib… | Patch early | 7.5 high | 5.8% | 2005-08-23 |
| CVE-2000-1174 EXP | Multiple buffer overflows in AFS ACL parser for Ethereal 0.8.13 and earlier allows remote attackers to execute arbitrary commands via a packet with a… | Patch early | 7.5 high | 5.8% | 2001-01-09 |
| CVE-2017-13783 EXP | An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… | Patch early | 8.8 high | 5.8% | 2017-11-13 |
| CVE-2017-13791 EXP | An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… | Patch early | 8.8 high | 5.8% | 2017-11-13 |
| CVE-2017-13796 EXP | An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affe… | Patch early | 8.8 high | 5.8% | 2017-11-13 |
| CVE-2010-2439 EXP | Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file). | Patch early | 9.3 high | 5.8% | 2010-06-24 |
| CVE-2008-6447 EXP | Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to execute arbitrary code via a… | Patch early | 9.3 high | 5.8% | 2009-03-09 |
| CVE-2009-1643 EXP | Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a crafted .m3u file. | Patch early | 9.3 high | 5.8% | 2009-05-15 |
| CVE-2009-1644 EXP | Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file. | Patch early | 9.3 high | 5.8% | 2009-05-15 |
| CVE-2015-3673 EXP | Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root p… | Patch early | 7.2 high | 5.8% | 2015-07-03 |
| CVE-2009-3221 EXP | Stack-based buffer overflow in Audio Lib Player (ALP) allows remote attackers to execute arbitrary code via a long URL in a .m3u playlist file. | Patch early | 9.3 high | 5.8% | 2009-09-16 |
| CVE-2006-6261 EXP | Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbit… | Patch early | 9.3 high | 5.8% | 2006-12-04 |
| CVE-2010-3125 EXP | Untrusted search path vulnerability in TeamMate Audit Management Software Suite 8.0 patch 2 allows local users, and possibly remote attackers, to exec… | Patch early | 9.3 high | 5.8% | 2010-08-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt