CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,851 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
187,224 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-8002 EXP | In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack… | Patch early | 8.8 high | 8% | 2018-03-09 |
| CVE-2006-2020 EXP | Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient acce… | Patch early | 7.8 high | 8% | 2006-04-25 |
| CVE-2005-3519 EXP | Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files… | Patch early | 7.5 high | 8% | 2005-11-06 |
| CVE-2000-0133 EXP | Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR co… | Patch early | 10.0 high | 8% | 2000-02-01 |
| CVE-2007-5156 EXP | Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS,… | Patch early | 7.5 high | 8% | 2007-10-01 |
| CVE-2017-16902 EXP | On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/logi… | Patch early | 7.5 high | 8% | 2017-11-20 |
| CVE-2014-5287 EXP | A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI)… | Patch early | 8.8 high | 8% | 2020-01-08 |
| CVE-2018-18865 EXP | The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosure… | Patch early | 8.1 high | 8% | 2018-11-20 |
| CVE-2004-2286 EXP | Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary… | Patch early | 7.5 high | 8% | 2004-12-31 |
| CVE-2006-4329 EXP | Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote attackers to execute arbitrary PH… | Patch early | 7.5 high | 8% | 2006-08-24 |
| CVE-2011-3493 EXP | Multiple stack-based buffer overflows in the DH_OneSecondTick function in Cogent DataHub 7.1.1.63 and earlier allow remote attackers to cause a denial… | Patch early | 10.0 high | 8% | 2011-09-16 |
| CVE-2019-9767 EXP | Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a c… | Patch early | 7.8 high | 8% | 2019-03-14 |
| CVE-2006-4125 EXP | Stack-based buffer overflow in main.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to execute arbitrary code via a large nickname, whi… | Patch early | 7.5 high | 8% | 2006-08-14 |
| CVE-2006-4611 EXP | Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitrary code via unspecified vector… | Patch early | 7.5 high | 8% | 2006-09-07 |
| CVE-2006-4952 EXP | The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail… | Patch early | 7.5 high | 8% | 2006-09-23 |
| CVE-2006-4954 EXP | The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information… | Patch early | 7.5 high | 8% | 2006-09-23 |
| CVE-2002-1652 EXP | Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a lo… | Patch early | 7.5 high | 8% | 2002-12-31 |
| CVE-2009-4840 EXP | Heap-based buffer overflow in the IAManager ActiveX control in IAManager.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code… | Patch early | 9.3 high | 8% | 2010-05-06 |
| CVE-2015-3000 EXP | SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity ref… | Patch early | 7.8 high | 8% | 2015-06-08 |
| CVE-2001-1109 EXP | Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST,… | Patch early | 7.5 high | 8% | 2001-09-12 |
| CVE-2017-16783 EXP | In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter. | Patch early | 9.8 critical | 8% | 2017-11-10 |
| CVE-2003-0409 EXP | Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via… | Patch early | 10.0 high | 8% | 2003-06-30 |
| CVE-2013-6227 EXP | Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allow… | Patch early | 7.5 high | 8% | 2014-12-27 |
| CVE-2019-9766 EXP | Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a c… | Patch early | 7.8 high | 8% | 2019-03-14 |
| CVE-2017-7061 EXP | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is… | Patch early | 8.8 high | 8% | 2017-07-20 |
| CVE-2022-29457 EXP | Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure dur… | Patch early | 8.8 high | 7.9% | 2022-04-18 |
| CVE-2008-1055 EXP | Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to… | Patch early | 7.5 high | 7.9% | 2008-02-27 |
| CVE-2025-52089 EXP | A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbi… | Patch early | 8.8 high | 7.9% | 2025-07-11 |
| CVE-2002-0504 EXP | Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers… | Patch early | 7.5 high | 7.9% | 2002-08-12 |
| CVE-2019-19245 EXP | NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quote… | Patch early | 9.8 critical | 7.9% | 2019-12-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt