CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,373 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
150,513 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-0338 EXP | Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with a large number of format stri… | Patch early | 7.5 high | 4.7% | 2007-01-18 |
| CVE-2015-2216 EXP | SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 4.7% | 2015-03-05 |
| CVE-2015-3325 EXP | SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL command… | Patch early | 7.5 high | 4.7% | 2015-05-15 |
| CVE-2002-2170 EXP | Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but… | Patch early | 7.5 high | 4.7% | 2002-12-31 |
| CVE-2018-9128 EXP | DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068. | Patch early | 7.8 high | 4.7% | 2018-04-01 |
| CVE-2015-7767 EXP | Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) v… | Patch early | 7.5 high | 4.7% | 2015-10-09 |
| CVE-2006-0671 EXP | Buffer overflow in Sony Ericsson K600i, V600i, W800i, and T68i cell phone allows remote attackers to cause a denial of service (reboot or shutdown) th… | Patch early | 7.8 high | 4.7% | 2006-02-13 |
| CVE-2007-2853 EXP | The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitrary commands via a command line… | Patch early | 10.0 high | 4.7% | 2007-05-24 |
| CVE-2004-0353 EXP | Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to gain priv… | Patch early | 10.0 high | 4.7% | 2004-11-23 |
| CVE-2008-2742 EXP | Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 thr… | Patch early | 7.5 high | 4.7% | 2008-06-17 |
| CVE-2008-5383 EXP | Stack-based buffer overflow in National Instruments Electronics Workbench allows user-assisted attackers to cause a denial of service (application cra… | Patch early | 9.3 high | 4.7% | 2008-12-09 |
| CVE-2013-2271 EXP | The D-Link DSL-2740B Gateway with firmware EU_1.0, when an active administrator session exists, allows remote attackers to bypass authentication and g… | Patch early | 7.6 high | 4.7% | 2013-11-19 |
| CVE-2017-2473 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchO… | Patch early | 7.8 high | 4.7% | 2017-04-02 |
| CVE-2007-1771 EXP | PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content System (WCS) 2.7.1 allows remote at… | Patch early | 9.3 high | 4.7% | 2007-03-30 |
| CVE-2012-5167 EXP | Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field para… | Patch early | 7.5 high | 4.7% | 2012-10-22 |
| CVE-2006-6884 EXP | Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remo… | Patch early | 9.3 high | 4.7% | 2006-12-31 |
| CVE-2005-1078 EXP | XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges. | Patch early | 7.5 high | 4.7% | 2005-04-12 |
| CVE-2024-23749 EXP | KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and va… | Patch early | 7.8 high | 4.7% | 2024-02-09 |
| CVE-2003-1179 EXP | Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path pa… | Patch early | 7.5 high | 4.7% | 2003-12-31 |
| CVE-2006-5291 EXP | PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1.4.2 allows remote attackers to execute arbi… | Patch early | 7.5 high | 4.7% | 2006-10-16 |
| CVE-2020-15478 EXP | The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors. | Patch early | 7.5 high | 4.7% | 2020-07-01 |
| CVE-2017-2515 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. Th… | Patch early | 8.8 high | 4.7% | 2017-05-22 |
| CVE-2000-1094 EXP | Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" command with a… | Patch early | 7.5 high | 4.7% | 2001-01-09 |
| CVE-2017-6371 EXP | Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string in the HTTP Referer header. | Patch early | 7.5 high | 4.7% | 2020-02-27 |
| CVE-2007-1657 EXP | Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-dependent attackers to execute arbit… | Patch early | 7.5 high | 4.7% | 2007-03-24 |
| CVE-2006-3292 EXP | SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with the "LIKE" k… | Patch early | 7.5 high | 4.7% | 2006-06-28 |
| CVE-2012-1239 EXP | The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x throug… | Patch early | 10.0 high | 4.7% | 2012-04-06 |
| CVE-2023-0963 EXP | A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the f… | Patch early | 7.3 high | 4.7% | 2023-02-22 |
| CVE-2017-6997 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… | Patch early | 7.8 high | 4.7% | 2017-05-22 |
| CVE-2017-6999 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. Th… | Patch early | 7.8 high | 4.7% | 2017-05-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt