CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,851 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
320,930 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-4663 EXP | TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharac… | Patch early | 6.8 medium | 9.8% | 2014-07-15 |
| CVE-2006-1243 EXP | Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitra… | Patch early | 7.5 high | 9.7% | 2006-03-15 |
| CVE-2007-2584 EXP | Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCente… | Patch early | 10.0 high | 9.7% | 2007-05-10 |
| CVE-2019-9832 EXP | The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that makes many socket connections t… | Patch early | 7.5 high | 9.7% | 2019-03-15 |
| CVE-2006-2026 EXP | Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly e… | Patch early | 6.5 medium | 9.7% | 2006-04-25 |
| CVE-2000-0908 EXP | BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Authorization or Referer MIME he… | Patch early | 5.0 medium | 9.7% | 2000-12-19 |
| CVE-1999-0879 EXP | Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file. | Patch early | 10.0 high | 9.7% | 1999-10-01 |
| CVE-2008-3702 EXP | Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit… | Patch early | 9.3 high | 9.7% | 2008-08-15 |
| CVE-2008-5406 EXP | Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application cras… | Patch early | 9.3 high | 9.7% | 2008-12-10 |
| CVE-2008-5691 EXP | Heap-based buffer overflow in the Phoenician Casino FlashAX ActiveX control 1.0.0.7 allows remote attackers to execute arbitrary code via a long argum… | Patch early | 9.3 high | 9.7% | 2008-12-19 |
| CVE-2006-4968 EXP | PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 9.7% | 2006-09-25 |
| CVE-2006-4913 EXP | Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files an… | Patch early | 7.5 high | 9.7% | 2006-09-21 |
| CVE-2019-11706 EXP | A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages… | Patch early | 7.5 high | 9.7% | 2019-07-23 |
| CVE-2004-0958 EXP | php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that… | Patch early | 5.0 medium | 9.7% | 2004-11-03 |
| CVE-2019-16902 EXP | In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying t… | Patch early | 7.5 high | 9.7% | 2019-09-27 |
| CVE-2001-1246 EXP | PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote… | Patch early | 7.5 high | 9.7% | 2001-06-30 |
| CVE-2018-7254 EXP | The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-r… | Patch early | 7.8 high | 9.7% | 2018-02-19 |
| CVE-2006-3682 EXP | awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) mont… | Patch early | 5.0 medium | 9.7% | 2006-07-21 |
| CVE-2021-40352 EXP | OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users. | Patch early | 6.5 medium | 9.7% | 2021-09-01 |
| CVE-2023-37979 EXP | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions. | Patch early | 7.1 high | 9.7% | 2023-07-27 |
| CVE-2017-11662 EXP | The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mi… | Patch early | 7.5 high | 9.7% | 2017-08-17 |
| CVE-2009-3241 EXP | Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a… | Patch early | 7.8 high | 9.7% | 2009-09-18 |
| CVE-2012-4514 EXP | rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a c… | Patch early | 5.0 medium | 9.7% | 2012-11-11 |
| CVE-2018-9010 EXP | Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page… | Patch early | 7.2 high | 9.7% | 2018-03-25 |
| CVE-2014-5074 EXP | Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device restart and STOP transition)… | Patch early | 7.1 high | 9.7% | 2014-08-17 |
| CVE-2000-0179 EXP | HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555. | Patch early | 5.0 medium | 9.7% | 2000-02-28 |
| CVE-1999-0182 EXP | Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password. | Patch early | 10.0 high | 9.7% | 1997-09-30 |
| CVE-2000-0775 EXP | Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or execute arbitrary commands via a… | Patch early | 7.5 high | 9.7% | 2000-10-20 |
| CVE-2000-0991 EXP | Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long t… | Patch early | 7.5 high | 9.7% | 2000-12-19 |
| CVE-2010-1316 EXP | Multiple stack-based buffer overflows in Tembria Server Monitor before 5.6.1 allow remote attackers to cause a denial of service (daemon crash) or pos… | Patch early | 5.0 medium | 9.7% | 2010-04-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt