CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,041 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
150,393 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-5705 EXP | The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier, when user triggers are enab… | Patch early | 9.3 high | 5.4% | 2008-12-22 |
| CVE-2000-0985 EXP | Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command. | Patch early | 10.0 high | 5.4% | 2000-12-19 |
| CVE-2013-1852 EXP | SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote attackers to execute arbitrary S… | Patch early | 7.5 high | 5.4% | 2014-02-05 |
| CVE-2017-4915 EXP | VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of… | Patch early | 7.8 high | 5.4% | 2017-05-22 |
| CVE-2007-2895 EXP | Buffer overflow in a certain ActiveX control in LTRDF14e.DLL 14.5.0.44 in LeadTools Raster Dialog File Object allows remote attackers to execute arbit… | Patch early | 7.5 high | 5.4% | 2007-05-30 |
| CVE-2008-4452 EXP | Buffer overflow in Cambridge Computer Corporation vxFtpSrv 2.0.3 allows remote attackers to cause a denial of service (crash and hang) and possibly ex… | Patch early | 9.0 high | 5.4% | 2008-10-06 |
| CVE-2001-0288 EXP | Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoo… | Patch early | 7.5 high | 5.4% | 2001-05-03 |
| CVE-2002-0328 EXP | Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies v… | Patch early | 7.5 high | 5.4% | 2002-06-25 |
| CVE-2005-3315 EXP | Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL comman… | Patch early | 7.5 high | 5.4% | 2005-10-30 |
| CVE-2007-1260 EXP | Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execute arbitrary code via a long st… | Patch early | 7.5 high | 5.4% | 2007-03-03 |
| CVE-2013-3532 EXP | SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 5.4% | 2013-05-10 |
| CVE-2008-2111 EXP | The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in t… | Patch early | 9.3 high | 5.4% | 2008-05-07 |
| CVE-2007-2487 EXP | Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3 file, a different vector than… | Patch early | 7.5 high | 5.4% | 2007-05-03 |
| CVE-2007-4060 EXP | Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attackers to execute arbitrary code… | Patch early | 9.0 high | 5.4% | 2007-07-30 |
| CVE-2017-3622 EXP | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (CDE)). The supported version th… | Patch early | 7.8 high | 5.4% | 2017-04-24 |
| CVE-2008-6935 EXP | Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cau… | Patch early | 10.0 high | 5.4% | 2009-08-11 |
| CVE-2004-1717 EXP | Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file wit… | Patch early | 7.5 high | 5.4% | 2004-08-16 |
| CVE-2023-34723 EXP | An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via /config/system.conf. | Patch early | 7.5 high | 5.4% | 2023-08-25 |
| CVE-2003-1210 EXP | Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands v… | Patch early | 7.5 high | 5.4% | 2003-12-31 |
| CVE-2008-0337 EXP | Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary c… | Patch early | 7.5 high | 5.4% | 2008-01-17 |
| CVE-2003-1160 EXP | FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.h… | Patch early | 10.0 high | 5.4% | 2003-10-30 |
| CVE-2005-0633 EXP | Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file. | Patch early | 7.5 high | 5.3% | 2005-03-02 |
| CVE-2009-0241 EXP | Stack-based buffer overflow in the process_path function in gmetad/server.c in Ganglia 3.1.1 allows remote attackers to cause a denial of service (cra… | Patch early | 7.5 high | 5.3% | 2009-01-21 |
| CVE-2023-30350 EXP | FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password. | Patch early | 8.8 high | 5.3% | 2023-05-29 |
| CVE-2002-0332 EXP | Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary code via (1) a long DNS hostna… | Patch early | 7.5 high | 5.3% | 2002-06-25 |
| CVE-2001-0442 EXP | Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbi… | Patch early | 7.5 high | 5.3% | 2001-06-27 |
| CVE-2010-4280 EXP | Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_g… | Patch early | 7.5 high | 5.3% | 2010-12-02 |
| CVE-2007-0016 EXP | Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a LST file. | Patch early | 7.5 high | 5.3% | 2007-01-03 |
| CVE-1999-0477 EXP | The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not… | Patch early | 7.5 high | 5.3% | 1999-12-25 |
| CVE-1999-0753 EXP | The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories. | Patch early | 7.5 high | 5.3% | 1999-08-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt