CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,173 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
150,443 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-3629 EXP | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11… | Patch early | 7.8 high | 5.1% | 2017-06-22 |
| CVE-2009-1422 EXP | Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to gain privi… | Patch early | 10.0 high | 5.1% | 2009-07-14 |
| CVE-2017-11322 EXP | The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) metac… | Patch early | 8.2 high | 5.1% | 2017-10-03 |
| CVE-2005-2651 EXP | gorum/prod.php in Zorum 3.5 allows remote attackers to execute arbitrary code via shell metacharacters in the argv parameter. | Patch early | 7.5 high | 5.1% | 2005-08-23 |
| CVE-2004-0733 EXP | Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via forma… | Patch early | 7.5 high | 5.1% | 2004-07-27 |
| CVE-2002-1452 EXP | Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter. | Patch early | 7.5 high | 5.1% | 2002-08-14 |
| CVE-2014-7178 EXP | Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP… | Patch early | 9.3 high | 5.1% | 2014-11-28 |
| CVE-2019-7652 EXP | TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker mus… | Patch early | 7.7 high | 5.1% | 2019-05-09 |
| CVE-2010-2701 EXP | Multiple buffer overflows in the FathFTP ActiveX control 1.7 allow remote attackers to execute arbitrary code via (1) the GetFromURL member or (2) a l… | Patch early | 9.3 high | 5.1% | 2010-07-12 |
| CVE-2009-1646 EXP | Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file. | Patch early | 9.3 high | 5.1% | 2009-05-15 |
| CVE-2003-0705 EXP | Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code. | Patch early | 7.5 high | 5.1% | 2003-09-17 |
| CVE-2008-7070 EXP | Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary commands via a " (quote) followe… | Patch early | 9.3 high | 5.1% | 2009-08-25 |
| CVE-2008-2922 EXP | Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of service (application crash) or pos… | Patch early | 7.5 high | 5% | 2008-06-30 |
| CVE-2008-2481 EXP | PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled,… | Patch early | 10.0 high | 5% | 2008-05-28 |
| CVE-2012-1198 EXP | base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents of the fil… | Patch early | 7.5 high | 5% | 2012-02-18 |
| CVE-2007-1391 EXP | PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arb… | Patch early | 10.0 high | 5% | 2007-03-10 |
| CVE-2002-2300 EXP | Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) via a long… | Patch early | 7.5 high | 5% | 2002-12-31 |
| CVE-2007-1416 EXP | PHP remote file inclusion vulnerability in createurl.php in JCcorp (aka James Coyle) URLshrink allows remote attackers to execute arbitrary PHP code v… | Patch early | 10.0 high | 5% | 2007-03-12 |
| CVE-2017-13847 EXP | An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "IOKit" compo… | Patch early | 7.8 high | 5% | 2017-12-25 |
| CVE-2014-9173 EXP | SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL… | Patch early | 7.5 high | 5% | 2014-12-02 |
| CVE-2011-1047 EXP | Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execut… | Patch early | 7.5 high | 5% | 2011-02-21 |
| CVE-2007-1195 EXP | Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: this is… | Patch early | 7.5 high | 5% | 2007-03-02 |
| CVE-2014-9097 EXP | Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed before 2014-07… | Patch early | 7.5 high | 5% | 2014-11-26 |
| CVE-2014-8358 EXP | Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP0… | Patch early | 7.8 high | 5% | 2017-12-11 |
| CVE-2007-0368 EXP | Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string in the MBSE_ROOT environment v… | Patch early | 10.0 high | 5% | 2007-01-19 |
| CVE-2007-1628 EXP | Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globals is enabled, allow remote at… | Patch early | 9.3 high | 5% | 2007-03-23 |
| CVE-2005-1873 EXP | Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command wi… | Patch early | 7.5 high | 5% | 2005-06-09 |
| CVE-2002-1891 EXP | Buffer overflow in IRCIT 0.3.1 IRC client allows remote attackers to execute arbitrary code via a long invite request. | Patch early | 7.5 high | 5% | 2002-12-31 |
| CVE-2000-0523 EXP | Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command. | Patch early | 10.0 high | 5% | 2000-06-06 |
| CVE-2016-1767 EXP | QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… | Patch early | 7.8 high | 5% | 2016-03-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt