CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,999 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
150,377 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-28142 EXP | CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete." | Patch early | 8.8 high | 5.8% | 2021-04-06 |
| CVE-2017-17738 EXP | The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html. | Patch early | 7.5 high | 5.8% | 2017-12-18 |
| CVE-2007-5487 EXP | Stack-based buffer overflow in COWON America jetAudio Basic 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a long URL in an… | Patch early | 9.3 high | 5.8% | 2007-10-16 |
| CVE-2008-1973 EXP | Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary cod… | Patch early | 9.3 high | 5.8% | 2008-04-27 |
| CVE-2007-2062 EXP | Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA allows user-assisted remote attackers to execute arbitrary code via a long FILE argument in… | Patch early | 9.3 high | 5.8% | 2007-04-18 |
| CVE-2008-7079 EXP | Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long… | Patch early | 9.3 high | 5.8% | 2009-08-25 |
| CVE-2009-1040 EXP | Buffer overflow in WinAsm Studio 5.1.5.0 allows user-assisted remote attackers to execute arbitrary code via a crafted project (.wap) file. | Patch early | 9.3 high | 5.8% | 2009-03-20 |
| CVE-2009-3811 EXP | Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag.… | Patch early | 9.3 high | 5.8% | 2009-10-27 |
| CVE-2009-4097 EXP | Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote attackers to execute arbitrary cod… | Patch early | 9.3 high | 5.8% | 2009-11-29 |
| CVE-2009-4863 EXP | Stack-based buffer overflow in UltraPlayer Media Player 2.112 allows remote attackers to execute arbitrary code via a long string in a .usk file. | Patch early | 9.3 high | 5.8% | 2010-05-11 |
| CVE-2010-2311 EXP | Stack-based buffer overflow in Power Tab Editor 1.7 build 80 allows user-assisted remote attackers to execute arbitrary code via a .ptb file with a lo… | Patch early | 9.3 high | 5.8% | 2010-06-16 |
| CVE-2023-0455 EXP | Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta. | Patch early | 8.8 high | 5.7% | 2023-01-26 |
| CVE-2002-0637 EXP | InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specification… | Patch early | 7.5 high | 5.7% | 2002-07-11 |
| CVE-2009-1212 EXP | Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datamatrix) allow remote attackers… | Patch early | 7.8 high | 5.7% | 2009-04-01 |
| CVE-2011-0498 EXP | Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to cause a den… | Patch early | 9.3 high | 5.7% | 2011-01-20 |
| CVE-2006-2399 EXP | Stack-based buffer overflow in the ServerNetworking::incoming_client_data function in servnet.cpp in Outgun 1.0.3 bot 2 and earlier allows remote atta… | Patch early | 7.5 high | 5.7% | 2006-05-16 |
| CVE-2006-3401 EXP | Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and possi… | Patch early | 7.5 high | 5.7% | 2006-07-06 |
| CVE-2002-0928 EXP | Buffer overflow in the Pirch 98 IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long hyperli… | Patch early | 7.5 high | 5.7% | 2002-10-04 |
| CVE-2002-1073 EXP | Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password. | Patch early | 7.5 high | 5.7% | 2002-10-04 |
| CVE-2002-1075 EXP | Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary co… | Patch early | 7.5 high | 5.7% | 2002-10-04 |
| CVE-2006-0628 EXP | myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the URL, which are not properly ha… | Patch early | 7.5 high | 5.7% | 2006-02-10 |
| CVE-2008-0221 EXP | Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch al… | Patch early | 9.3 high | 5.7% | 2008-01-10 |
| CVE-2012-5340 EXP | SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file. | Patch early | 7.8 high | 5.7% | 2020-01-23 |
| CVE-2006-4781 EXP | Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of service (crash) or possibly e… | Patch early | 7.5 high | 5.7% | 2006-09-14 |
| CVE-2012-2627 EXP | d4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrite… | Patch early | 9.4 high | 5.7% | 2012-07-31 |
| CVE-2013-1468 EXP | Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authentic… | Patch early | 7.6 high | 5.7% | 2013-03-14 |
| CVE-2008-6731 EXP | Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arbitrary PHP code by uploading a… | Patch early | 9.3 high | 5.7% | 2009-04-20 |
| CVE-2008-6959 EXP | Insecure method vulnerability in the Chilkat Socket ActiveX control (ChilkatSocket.ChilkatSocket.1) in ChilkatSocket.dll 2.3.1.1 allows remote attacke… | Patch early | 9.3 high | 5.7% | 2009-08-12 |
| CVE-2008-1690 EXP | WebContainer.exe 1.0.0.336 and earlier in SLMail Pro 6.3.1.0 and earlier allows remote attackers to cause a denial of service (memory corruption and d… | Patch early | 10.0 high | 5.7% | 2008-04-07 |
| CVE-2008-6841 EXP | PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_dbquery) component 1.4.1.1 and… | Patch early | 7.5 high | 5.7% | 2009-07-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt