CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,829 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
187,214 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-4323 EXP | Heap-based buffer overflow in novell-tftp.exe in Novell ZENworks Configuration Manager (ZCM) 10.3.1, 10.3.2, and 11.0, and earlier versions, allows re… | Patch early | 7.5 high | 8.1% | 2011-02-19 |
| CVE-2023-1934 EXP | The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Pres… | Patch early | 9.8 critical | 8.1% | 2023-05-12 |
| CVE-2017-9742 EXP | The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and appl… | Patch early | 7.8 high | 8.1% | 2017-06-19 |
| CVE-2017-9750 EXP | opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (b… | Patch early | 7.8 high | 8.1% | 2017-06-19 |
| CVE-2017-9756 EXP | The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overf… | Patch early | 7.8 high | 8.1% | 2017-06-19 |
| CVE-2005-3405 EXP | ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addsla… | Patch early | 7.5 high | 8.1% | 2005-11-01 |
| CVE-2008-0729 EXP | Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain Ja… | Patch early | 7.1 high | 8.1% | 2008-02-12 |
| CVE-2006-1749 EXP | PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the retu… | Patch early | 7.5 high | 8.1% | 2006-04-12 |
| CVE-2003-0304 EXP | one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Ins… | Patch early | 10.0 high | 8.1% | 2003-06-09 |
| CVE-1999-1508 EXP | Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented UR… | Patch early | 10.0 high | 8.1% | 1999-11-16 |
| CVE-2018-7316 EXP | Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action. | Patch early | 9.8 critical | 8.1% | 2018-02-22 |
| CVE-2014-4912 EXP | An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation. | Patch early | 9.8 critical | 8.1% | 2018-03-22 |
| CVE-2015-1371 EXP | Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an exe… | Patch early | 7.5 high | 8.1% | 2015-01-27 |
| CVE-2000-1093 EXP | Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command. | Patch early | 7.5 high | 8.1% | 2001-01-09 |
| CVE-1999-1521 EXP | Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attac… | Patch early | 10.0 high | 8.1% | 1999-09-12 |
| CVE-2008-0763 EXP | Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arb… | Patch early | 10.0 high | 8.1% | 2008-02-13 |
| CVE-2002-1656 EXP | X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or th… | Patch early | 7.5 high | 8.1% | 2002-12-31 |
| CVE-2017-14523 EXP | WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that ex… | Patch early | 7.5 high | 8% | 2018-01-26 |
| CVE-2017-6823 EXP | Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action. | Patch early | 8.8 high | 8% | 2017-03-12 |
| CVE-2007-0873 EXP | nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_ed… | Patch early | 7.5 high | 8% | 2007-02-12 |
| CVE-2017-2491 EXP | Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remote attackers to execute arbitra… | Patch early | 8.8 high | 8% | 2017-06-27 |
| CVE-2007-2371 EXP | admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows re… | Patch early | 10.0 high | 8% | 2007-04-30 |
| CVE-2013-1638 EXP | Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document. | Patch early | 9.3 high | 8% | 2013-02-08 |
| CVE-2007-2317 EXP | Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow… | Patch early | 7.5 high | 8% | 2007-04-26 |
| CVE-2007-2891 EXP | Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_da… | Patch early | 7.5 high | 8% | 2007-05-30 |
| CVE-2002-0733 EXP | Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, whi… | Patch early | 7.5 high | 8% | 2002-08-12 |
| CVE-2007-2429 EXP | ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for t… | Patch early | 10.0 high | 8% | 2007-05-02 |
| CVE-2017-7056 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 8% | 2017-07-20 |
| CVE-2008-3317 EXP | admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar… | Patch early | 7.5 high | 8% | 2008-07-25 |
| CVE-2008-2888 EXP | Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attackers to execute arbitrary PHP… | Patch early | 10.0 high | 8% | 2008-06-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt