CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,708 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
187,140 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2001-0507 EXP | IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka th… | Patch early | 7.2 high | 8.8% | 2001-09-20 |
| CVE-1999-0204 EXP | Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. | Patch early | 10.0 high | 8.8% | 1997-01-01 |
| CVE-2008-2214 EXP | Stack-based buffer overflow in the Network Manager in Castle Rock Computing SNMPc 7.1 and earlier allows remote attackers to cause a denial of service… | Patch early | 10.0 high | 8.8% | 2008-05-14 |
| CVE-2017-8311 EXP | Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to e… | Patch early | 7.8 high | 8.8% | 2017-05-23 |
| CVE-2017-4914 EXP | VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote at… | Patch early | 9.8 critical | 8.8% | 2017-06-07 |
| CVE-2013-2267 EXP | PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system. | Patch early | 7.2 high | 8.8% | 2020-01-27 |
| CVE-2014-2846 EXP | Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remot… | Patch early | 7.5 high | 8.8% | 2014-04-28 |
| CVE-2004-1259 EXP | Multiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute arbitrary code via crafted ABC… | Patch early | 10.0 high | 8.8% | 2005-01-10 |
| CVE-2004-1261 EXP | Multiple buffer overflows in the preparse function in asp2php 0.76.23 allow remote attackers to execute arbitrary code via crafted ASP scripts. | Patch early | 10.0 high | 8.8% | 2005-01-10 |
| CVE-2004-1298 EXP | Buffer overflow in the parse function in vb2c.c for vb2c 0.02 allows remote attackers to execute arbitrary code via a crafted FRM file. | Patch early | 10.0 high | 8.8% | 2005-01-10 |
| CVE-2026-27483 EXP | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in… | Patch early | 8.8 high | 8.8% | 2026-02-24 |
| CVE-2007-5610 EXP | The DeleteSingleFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows re… | Patch early | 10.0 high | 8.8% | 2008-06-04 |
| CVE-2008-0953 EXP | The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote att… | Patch early | 10.0 high | 8.8% | 2008-06-04 |
| CVE-2015-7112 EXP | The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code i… | Patch early | 9.3 high | 8.8% | 2015-12-11 |
| CVE-2006-4992 EXP | Multiple PHP remote file inclusion vulnerabilities in JD-WordPress for Joomla! (com_jd-wp) 2.0-1.0 RC2 allow remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 8.8% | 2006-09-26 |
| CVE-2006-7136 EXP | Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code v… | Patch early | 10.0 high | 8.8% | 2007-03-07 |
| CVE-2005-3640 EXP | Multiple buffer overflows in the IMAP Groupware Mail server of Floosietek FTGate (FTGate4) 4.1 allow remote attackers to execute arbitrary code via lo… | Patch early | 10.0 high | 8.8% | 2005-11-16 |
| CVE-2017-11456 EXP | Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configura… | Patch early | 7.5 high | 8.8% | 2017-07-19 |
| CVE-2009-1092 EXP | Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to… | Patch early | 9.3 high | 8.8% | 2009-03-25 |
| CVE-2026-3576 EXP | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions… | Patch early | 7.2 high | 8.8% | 2026-07-11 |
| CVE-2006-6958 EXP | Multiple PHP remote file inclusion vulnerabilities in phpBlueDragon 2.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the vsDrag… | Patch early | 7.5 high | 8.8% | 2007-01-29 |
| CVE-2017-17111 EXP | Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request. | Patch early | 9.8 critical | 8.8% | 2017-12-11 |
| CVE-2005-3262 EXP | Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE… | Patch early | 7.5 high | 8.8% | 2005-10-20 |
| CVE-2017-10309 EXP | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u144 and 9. Ea… | Patch early | 7.1 high | 8.8% | 2017-10-19 |
| CVE-2009-0389 EXP | Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwri… | Patch early | 9.3 high | 8.8% | 2009-02-02 |
| CVE-2019-12323 EXP | The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS. | Patch early | 7.5 high | 8.8% | 2019-06-24 |
| CVE-2006-1213 EXP | JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direc… | Patch early | 7.5 high | 8.8% | 2006-03-14 |
| CVE-2021-31762 EXP | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse s… | Patch early | 8.8 high | 8.8% | 2021-04-25 |
| CVE-2008-1331 EXP | cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allo… | Patch early | 10.0 high | 8.8% | 2008-04-02 |
| CVE-2007-2946 EXP | Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows remote attackers to cause a den… | Patch early | 10.0 high | 8.8% | 2007-05-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt