CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,893 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
320,982 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2079 EXP | The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the database server hostname, whic… | Patch early | 9.3 high | 9.7% | 2007-04-18 |
| CVE-2010-1813 EXP | WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory cor… | Patch early | 6.8 medium | 9.7% | 2010-09-09 |
| CVE-2016-3542 EXP | Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 a… | Patch early | 6.5 medium | 9.7% | 2016-07-21 |
| CVE-2003-0436 EXP | Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter. | Patch early | 7.5 high | 9.7% | 2003-07-24 |
| CVE-2019-1943 EXP | A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacke… | Patch early | 4.7 medium | 9.7% | 2019-07-17 |
| CVE-2008-6998 EXP | Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assis… | Patch early | 9.3 high | 9.7% | 2009-08-19 |
| CVE-2006-5307 EXP | Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the Htmls p… | Patch early | 7.5 high | 9.7% | 2006-10-17 |
| CVE-2002-2272 EXP | Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronize… | Patch early | 7.8 high | 9.7% | 2002-12-31 |
| CVE-2016-10277 EXP | An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the con… | Patch early | 7.8 high | 9.7% | 2017-05-12 |
| CVE-2008-6497 EXP | The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTTP requests for the /- URI. | Patch early | 7.8 high | 9.7% | 2009-03-20 |
| CVE-2003-0169 EXP | hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via… | Patch early | 5.0 medium | 9.7% | 2003-04-11 |
| CVE-2005-2967 EXP | Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute a… | Patch early | 7.5 high | 9.7% | 2005-10-14 |
| CVE-2007-2609 EXP | Multiple PHP remote file inclusion vulnerabilities in gnuedu 1.3b2 allow remote attackers to execute arbitrary PHP code via a URL in the (a) ETCDIR pa… | Patch early | 7.5 high | 9.7% | 2007-05-11 |
| CVE-2018-15576 EXP | An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in… | Patch early | 8.1 high | 9.7% | 2018-08-24 |
| CVE-1999-0913 EXP | dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters. | Patch early | 10.0 high | 9.7% | 1999-08-05 |
| CVE-2005-4553 EXP | Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long APPE command. NOTE: the provenance of this inf… | Patch early | 7.5 high | 9.7% | 2005-12-28 |
| CVE-2008-3408 EXP | Stack-based buffer overflow in CoolPlayer 2.18, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a cra… | Patch early | 6.8 medium | 9.7% | 2008-07-31 |
| CVE-2004-0486 EXP | HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue tha… | Patch early | 7.6 high | 9.7% | 2004-07-07 |
| CVE-2017-0259 EXP | The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows… | Patch early | 4.7 medium | 9.7% | 2017-05-12 |
| CVE-2009-0410 EXP | Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remot… | Patch early | 10.0 high | 9.7% | 2009-02-03 |
| CVE-2006-0717 EXP | IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532… | Patch early | 5.0 medium | 9.7% | 2006-02-15 |
| CVE-2008-2006 EXP | Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to cause a denial of service (NULL pointer dereference… | Patch early | 4.3 medium | 9.7% | 2008-05-22 |
| CVE-2007-0165 EXP | Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests tha… | Patch early | 7.8 high | 9.7% | 2007-01-10 |
| CVE-2007-2142 EXP | Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix pa… | Patch early | 7.5 high | 9.7% | 2007-04-19 |
| CVE-2007-2762 EXP | Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbitrary PHP code via a URL in (1)… | Patch early | 7.5 high | 9.7% | 2007-05-18 |
| CVE-1999-1431 EXP | ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), inst… | Patch early | 4.6 medium | 9.7% | 2005-01-07 |
| CVE-2005-1173 EXP | Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request. | Patch early | 7.5 high | 9.7% | 2005-05-02 |
| CVE-2018-4328 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTun… | Patch early | 8.8 high | 9.7% | 2019-04-03 |
| CVE-2020-11699 EXP | An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute… | Patch early | 8.8 high | 9.6% | 2020-09-17 |
| CVE-2009-1672 EXP | The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (… | Patch early | 9.3 high | 9.6% | 2009-05-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt