CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,908 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
320,993 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1486 EXP | Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly… | Patch early | 7.5 high | 9.4% | 2003-04-02 |
| CVE-2001-0784 EXP | Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack us… | Patch early | 5.0 medium | 9.4% | 2001-10-18 |
| CVE-2015-7945 EXP | The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13… | Patch early | 7.5 high | 9.4% | 2017-08-18 |
| CVE-2004-2631 EXP | Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary P… | Patch early | 7.5 high | 9.4% | 2004-12-31 |
| CVE-2007-0634 EXP | Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packe… | Patch early | 7.8 high | 9.4% | 2007-01-31 |
| CVE-2018-16946 EXP | LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log &… | Patch early | 7.5 high | 9.3% | 2018-09-12 |
| CVE-2018-4306 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.3% | 2019-04-03 |
| CVE-2018-4312 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.3% | 2019-04-03 |
| CVE-2018-4317 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.3% | 2019-04-03 |
| CVE-2018-4318 EXP | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 fo… | Patch early | 8.8 high | 9.3% | 2019-04-03 |
| CVE-2007-1014 EXP | Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitr… | Patch early | 10.0 high | 9.3% | 2007-02-21 |
| CVE-2009-3840 EXP | The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to cause a d… | Patch early | 5.0 medium | 9.3% | 2009-11-19 |
| CVE-2010-0519 EXP | Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (applicat… | Patch early | 6.8 medium | 9.3% | 2010-03-30 |
| CVE-2007-0051 EXP | Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary c… | Patch early | 6.8 medium | 9.3% | 2007-01-04 |
| CVE-2001-0009 EXP | Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack. | Patch early | 5.0 medium | 9.3% | 2001-02-12 |
| CVE-2007-4255 EXP | Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long first argument to the msql_… | Patch early | 7.5 high | 9.3% | 2007-08-08 |
| CVE-2012-0298 EXP | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitrar… | Patch early | 6.4 medium | 9.3% | 2012-05-21 |
| CVE-2004-0129 EXP | Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) seque… | Patch early | 5.0 medium | 9.3% | 2004-03-03 |
| CVE-2004-1988 EXP | PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by… | Patch early | 7.5 high | 9.3% | 2004-04-30 |
| CVE-2004-1989 EXP | PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modif… | Patch early | 7.5 high | 9.3% | 2004-04-30 |
| CVE-2005-4694 EXP | Unspecified vulnerability in the www_add method in Asset.pm in Plain Black WebGUI 6.3.0 and other versions before 6.7.6 allows attackers to execute ar… | Patch early | 7.5 high | 9.3% | 2005-12-31 |
| CVE-2006-6493 EXP | Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable… | Patch early | 5.1 medium | 9.3% | 2006-12-13 |
| CVE-2004-1796 EXP | PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header]… | Patch early | 7.5 high | 9.3% | 2004-12-31 |
| CVE-2001-1002 EXP | The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by… | Patch early | 7.5 high | 9.3% | 2001-08-31 |
| CVE-2009-0641 EXP | sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older… | Patch early | 9.3 high | 9.3% | 2009-02-20 |
| CVE-2005-2108 EXP | SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that… | Patch early | 7.5 high | 9.3% | 2005-07-05 |
| CVE-2007-2540 EXP | Multiple PHP remote file inclusion vulnerabilities in PMECMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the con… | Patch early | 7.5 high | 9.3% | 2007-05-09 |
| CVE-2011-5233 EXP | Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pi… | Patch early | 4.3 medium | 9.3% | 2012-10-25 |
| CVE-2010-2004 EXP | Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assisted remote attackers to execute… | Patch early | 9.3 high | 9.3% | 2010-05-20 |
| CVE-2007-4391 EXP | Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application cras… | Patch early | 9.3 high | 9.3% | 2007-08-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt