CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
402,941 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-2765 EXP | The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process… | Patch early | 5.0 medium | 13.7% | 2013-07-15 |
| CVE-2009-4491 EXP | thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or… | Patch early | 9.8 critical | 13.7% | 2010-01-13 |
| CVE-2003-0078 EXP | ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding… | Patch early | 5.0 medium | 13.7% | 2003-03-03 |
| CVE-2005-3684 EXP | Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a denial of service (application c… | Patch early | 7.5 high | 13.7% | 2005-11-19 |
| CVE-2010-3146 EXP | Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2)… | Patch early | 9.3 high | 13.7% | 2010-08-27 |
| CVE-2019-6971 EXP | An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management web… | Patch early | 9.8 critical | 13.7% | 2019-06-19 |
| CVE-2011-0614 EXP | Buffer overflow in Adobe Audition 3.0.1 and earlier allows remote attackers to cause a denial of service (memory corruption and application crash) or… | Patch early | 9.3 high | 13.7% | 2011-05-16 |
| CVE-2019-6442 EXP | An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, rel… | Patch early | 6.5 medium | 13.7% | 2019-01-16 |
| CVE-2004-1293 EXP | Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF fil… | Patch early | 10.0 high | 13.7% | 2005-01-10 |
| CVE-2010-2918 EXP | PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows re… | Patch early | 7.5 high | 13.7% | 2010-07-30 |
| CVE-2002-0814 EXP | Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via… | Patch early | 7.5 high | 13.7% | 2002-08-12 |
| CVE-2009-1247 EXP | SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL commands via the username param… | Patch early | 7.5 high | 13.7% | 2009-04-06 |
| CVE-2011-2443 EXP | Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of service (memory corruption and appli… | Patch early | 9.3 high | 13.7% | 2011-10-04 |
| CVE-2003-0447 EXP | The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument t… | Patch early | 5.1 medium | 13.7% | 2003-07-24 |
| CVE-2017-16353 EXP | GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file… | Patch early | 6.5 medium | 13.7% | 2017-11-01 |
| CVE-2003-0963 EXP | Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via l… | Patch early | 7.5 high | 13.7% | 2004-01-05 |
| CVE-2017-8870 EXP | Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file. | Patch early | 7.8 high | 13.7% | 2017-07-27 |
| CVE-2002-1603 EXP | GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /),… | Patch early | 5.0 medium | 13.7% | 2002-02-13 |
| CVE-2007-3536 EXP | Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via… | Patch early | 7.6 high | 13.7% | 2007-07-03 |
| CVE-2007-0562 EXP | Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (applicat… | Patch early | 4.3 medium | 13.7% | 2007-01-30 |
| CVE-2008-3657 EXP | The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of input… | Patch early | 7.5 high | 13.7% | 2008-08-13 |
| CVE-2002-1484 EXP | DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other sy… | Patch early | 9.8 critical | 13.7% | 2003-04-22 |
| CVE-2009-1759 EXP | Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, a… | Patch early | 9.3 high | 13.7% | 2009-05-22 |
| CVE-2010-4254 EXP | Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote a… | Patch early | 7.5 high | 13.6% | 2010-12-06 |
| CVE-2012-3577 EXP | Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to ex… | Patch early | 7.5 high | 13.6% | 2012-06-17 |
| CVE-2025-50286 EXP | A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct… | Patch early | 8.1 high | 13.6% | 2025-08-06 |
| CVE-2022-30286 EXP | pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code. | Patch early | 7.5 high | 13.6% | 2022-05-09 |
| CVE-2010-3144 EXP | Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local user… | Patch early | 9.3 high | 13.6% | 2010-08-27 |
| CVE-2010-3148 EXP | Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the curr… | Patch early | 9.3 high | 13.6% | 2010-08-27 |
| CVE-2007-2052 EXP | Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the… | Patch early | 5.0 medium | 13.6% | 2007-04-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt