CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,829 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
187,214 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-9614 EXP | The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and ap… | Patch early | 8.8 high | 8.2% | 2017-07-27 |
| CVE-2019-11369 EXP | An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensiti… | Patch early | 8.8 high | 8.1% | 2019-06-03 |
| CVE-2003-0118 EXP | SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attacker… | Patch early | 7.5 high | 8.1% | 2003-05-12 |
| CVE-2006-4849 EXP | PHP remote file inclusion vulnerability in header.php in MobilePublisherPHP 1.5 RC2 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 8.1% | 2006-09-19 |
| CVE-2007-3956 EXP | TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause… | Patch early | 7.8 high | 8.1% | 2007-07-24 |
| CVE-2006-4204 EXP | Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP code via a UR… | Patch early | 7.5 high | 8.1% | 2006-08-17 |
| CVE-2006-4477 EXP | Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empt… | Patch early | 7.5 high | 8.1% | 2006-08-31 |
| CVE-2013-4984 EXP | The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain… | Patch early | 7.2 high | 8.1% | 2013-09-10 |
| CVE-2007-1043 EXP | Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config… | Patch early | 7.5 high | 8.1% | 2007-02-21 |
| CVE-2006-6853 EXP | Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary code via a long string in a cra… | Patch early | 10.0 high | 8.1% | 2006-12-31 |
| CVE-2018-4241 EXP | An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchO… | Patch early | 7.8 high | 8.1% | 2018-06-08 |
| CVE-2024-50477 EXP | Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentica… | Patch early | 9.8 critical | 8.1% | 2024-10-28 |
| CVE-1999-1533 EXP | Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file i… | Patch early | 7.5 high | 8.1% | 1999-11-07 |
| CVE-2019-9623 EXP | Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php. | Patch early | 9.8 critical | 8.1% | 2019-03-07 |
| CVE-2014-7288 EXP | Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell c… | Patch early | 9.0 high | 8.1% | 2015-02-01 |
| CVE-2015-6787 EXP | Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact v… | Patch early | 10.0 high | 8.1% | 2015-12-06 |
| CVE-1999-0950 EXP | Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. | Patch early | 10.0 high | 8.1% | 1999-10-28 |
| CVE-2009-4202 EXP | Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include a… | Patch early | 7.5 high | 8.1% | 2009-12-04 |
| CVE-2014-9304 EXP | Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrativ… | Patch early | 7.5 high | 8.1% | 2014-12-07 |
| CVE-2019-7671 EXP | Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may a… | Patch early | 9.0 critical | 8.1% | 2019-06-05 |
| CVE-2002-1014 EXP | Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an… | Patch early | 7.5 high | 8.1% | 2002-10-04 |
| CVE-2008-3318 EXP | admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar… | Patch early | 7.5 high | 8.1% | 2008-07-25 |
| CVE-2026-1830 EXP | The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insuffici… | Patch early | 9.8 critical | 8.1% | 2026-04-09 |
| CVE-2001-0183 EXP | ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes t… | Patch early | 7.5 high | 8.1% | 2001-03-26 |
| CVE-2001-0192 EXP | Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions. | Patch early | 10.0 high | 8.1% | 2001-05-03 |
| CVE-2004-0286 EXP | Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… | Patch early | 10.0 high | 8.1% | 2004-11-23 |
| CVE-2002-0006 EXP | XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clien… | Patch early | 7.5 high | 8.1% | 2002-06-25 |
| CVE-2014-9633 EXP | The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device handle, which triggers a NULL po… | Patch early | 7.5 high | 8.1% | 2015-02-03 |
| CVE-2006-5395 EXP | Buffer overflow in Microsoft Class Package Export Tool (aka clspack.exe) allows context-dependent attackers to execute arbitrary code via a long strin… | Patch early | 7.5 high | 8.1% | 2006-10-18 |
| CVE-2007-6189 EXP | A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitr… | Patch early | 9.3 high | 8.1% | 2007-11-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt