CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,041 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
403,041 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-2957 EXP | Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to… | Patch early | 6.8 medium | 12.7% | 2009-09-02 |
| CVE-2014-9611 EXP | Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/in… | Patch early | 9.8 critical | 12.7% | 2017-09-19 |
| CVE-2011-4107 EXP | The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 a… | Patch early | 6.5 medium | 12.7% | 2011-11-17 |
| CVE-2014-6395 EXP | Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to caus… | Patch early | 7.5 high | 12.7% | 2014-12-19 |
| CVE-2019-0948 EXP | An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when it improperly parses XML input containing a reference t… | Patch early | 4.7 medium | 12.7% | 2019-06-12 |
| CVE-2016-1757 EXP | Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context via a… | Patch early | 7.0 high | 12.7% | 2016-03-24 |
| CVE-2014-4019 EXP | ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows… | Patch early | 7.5 high | 12.7% | 2020-02-20 |
| CVE-2010-2094 EXP | Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information… | Patch early | 6.8 medium | 12.7% | 2010-05-27 |
| CVE-2005-3539 EXP | Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in… | Patch early | 7.5 high | 12.7% | 2005-12-31 |
| CVE-2009-0696 EXP | The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a… | Patch early | 4.3 medium | 12.6% | 2009-07-29 |
| CVE-2008-5692 EXP | Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via… | Patch early | 5.0 medium | 12.6% | 2008-12-19 |
| CVE-2017-1002002 EXP | Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/ | Patch early | 9.8 critical | 12.6% | 2017-09-14 |
| CVE-2010-0168 EXP | The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.6… | Patch early | 7.6 high | 12.6% | 2010-03-25 |
| CVE-2011-4620 EXP | Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote a… | Patch early | 9.3 high | 12.6% | 2011-12-31 |
| CVE-2017-14459 EXP | An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a… | Patch early | 10.0 critical | 12.6% | 2018-04-11 |
| CVE-1999-0977 EXP | Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request. | Patch early | 10.0 high | 12.6% | 1999-12-10 |
| CVE-2000-0743 EXP | Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (G… | Patch early | 10.0 high | 12.6% | 2000-10-20 |
| CVE-2013-0804 EXP | The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of ser… | Patch early | 10.0 high | 12.6% | 2013-02-24 |
| CVE-2015-2844 EXP | The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $actio… | Patch early | 10.0 high | 12.6% | 2015-05-12 |
| CVE-2001-0700 EXP | Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header. | Patch early | 7.5 high | 12.6% | 2001-09-20 |
| CVE-2009-1490 EXP | Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrar… | Patch early | 5.0 medium | 12.6% | 2009-05-05 |
| CVE-2013-6881 EXP | CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the… | Patch early | 10.0 high | 12.6% | 2014-01-07 |
| CVE-2007-6638 EXP | March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user… | Patch early | 10.0 high | 12.6% | 2008-01-04 |
| CVE-2012-4513 EXP | khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via la… | Patch early | 6.4 medium | 12.6% | 2012-11-11 |
| CVE-2019-11444 EXP | An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be ex… | Patch early | 7.2 high | 12.6% | 2019-04-22 |
| CVE-2005-4134 EXP | Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and dela… | Patch early | 5.0 medium | 12.6% | 2005-12-09 |
| CVE-2017-5415 EXP | An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and furthe… | Patch early | 5.3 medium | 12.6% | 2018-06-11 |
| CVE-2018-11509 EXP | ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from t… | Patch early | 9.8 critical | 12.6% | 2018-08-16 |
| CVE-2021-25159 EXP | A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x… | Patch early | 6.5 medium | 12.6% | 2021-03-30 |
| CVE-2001-0022 EXP | simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter… | Patch early | 10.0 high | 12.6% | 2001-02-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt