CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,286 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
150,481 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-3213 EXP | Stack-based buffer overflow in broid 1.0 Beta 3a allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrar… | Patch early | 9.3 high | 4.9% | 2009-09-16 |
| CVE-2015-3314 EXP | SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5. | Patch early | 8.1 high | 4.9% | 2017-09-07 |
| CVE-1999-1531 EXP | Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SR… | Patch early | 7.5 high | 4.9% | 1999-11-02 |
| CVE-2008-0986 EXP | Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote att… | Patch early | 7.5 high | 4.9% | 2008-03-06 |
| CVE-2010-2099 EXP | bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows rem… | Patch early | 7.5 high | 4.9% | 2010-05-27 |
| CVE-2016-1247 EXP | The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04… | Patch early | 7.8 high | 4.9% | 2016-11-29 |
| CVE-2007-1393 EXP | PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary PHP code via a URL in the file… | Patch early | 10.0 high | 4.9% | 2007-03-10 |
| CVE-2007-1787 EXP | Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is ena… | Patch early | 9.3 high | 4.9% | 2007-03-31 |
| CVE-2008-1044 EXP | Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QSP2IE) in qsp2ie07076007.dll 7.… | Patch early | 7.5 high | 4.8% | 2008-02-27 |
| CVE-2016-1846 EXP | The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary… | Patch early | 7.8 high | 4.8% | 2016-05-20 |
| CVE-2007-0683 EXP | PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 4.8% | 2007-02-03 |
| CVE-2006-2107 EXP | Buffer overflow in BL4 SMTP Server 0.1.4 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long… | Patch early | 7.5 high | 4.8% | 2006-04-29 |
| CVE-2006-3400 EXP | Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attack… | Patch early | 7.5 high | 4.8% | 2006-07-06 |
| CVE-2007-1013 EXP | PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote attackers to execute arbitrary… | Patch early | 10.0 high | 4.8% | 2007-02-21 |
| CVE-2007-2538 EXP | SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via th… | Patch early | 7.5 high | 4.8% | 2007-05-09 |
| CVE-2007-3539 EXP | Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL comma… | Patch early | 7.5 high | 4.8% | 2007-07-03 |
| CVE-2007-4419 EXP | Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cook… | Patch early | 9.3 high | 4.8% | 2007-08-18 |
| CVE-2004-0940 EXP | Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary… | Patch early | 7.8 high | 4.8% | 2005-02-09 |
| CVE-2009-4107 EXP | Buffer overflow in Invisible Browsing 5.0.52 allows user-assisted remote attackers to execute arbitrary code via a crafted .ibkey file containing a lo… | Patch early | 9.3 high | 4.8% | 2009-11-29 |
| CVE-2009-4757 EXP | Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (application crash) or possibly exe… | Patch early | 9.3 high | 4.8% | 2010-03-29 |
| CVE-2009-1356 EXP | Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 filename in a playlist (.xpl) fi… | Patch early | 9.3 high | 4.8% | 2009-04-21 |
| CVE-2006-2315 EXP | PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 4.8% | 2006-05-12 |
| CVE-2008-5010 EXP | in.dhcpd in the DHCP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows remote attackers to cause a denial of service… | Patch early | 10.0 high | 4.8% | 2008-11-10 |
| CVE-2015-7235 EXP | Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers… | Patch early | 7.5 high | 4.8% | 2015-09-17 |
| CVE-2000-0586 EXP | Buffer overflow in Dalnet IRC server 4.6.5 allows remote attackers to cause a denial of service or execute arbitrary commands via the SUMMON command. | Patch early | 10.0 high | 4.8% | 2000-06-29 |
| CVE-2007-5653 EXP | The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-depe… | Patch early | 9.3 high | 4.8% | 2007-10-23 |
| CVE-2009-4372 EXP | AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute a… | Patch early | 7.5 high | 4.8% | 2009-12-21 |
| CVE-2008-7022 EXP | Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows remote atta… | Patch early | 9.3 high | 4.8% | 2009-08-21 |
| CVE-2002-0280 EXP | Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP… | Patch early | 7.5 high | 4.8% | 2002-05-31 |
| CVE-2005-1702 EXP | Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 4.8% | 2005-05-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt