CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,286 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
403,286 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-0134 EXP | Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is su… | Patch early | 7.5 high | 11.7% | 2007-01-09 |
| CVE-2000-0256 EXP | Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise av… | Patch early | 7.5 high | 11.7% | 2000-04-19 |
| CVE-2017-6506 EXP | In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. T… | Patch early | 9.8 critical | 11.7% | 2017-03-10 |
| CVE-2019-12744 EXP | SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018… | Patch early | 7.5 high | 11.7% | 2019-06-20 |
| CVE-2007-5722 EXP | Stack-based buffer overflow in a certain ActiveX control in GLChat.ocx 2.5.1.32 in GlobalLink 2.7.0.8, as used in Ourgame GLWorld and possibly other p… | Patch early | 7.5 high | 11.7% | 2007-10-30 |
| CVE-2013-4295 EXP | The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external… | Patch early | 5.0 medium | 11.7% | 2013-10-24 |
| CVE-2019-9768 EXP | Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for… | Patch early | 7.5 high | 11.7% | 2019-03-14 |
| CVE-2017-3897 EXP | A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security… | Patch early | 9.8 critical | 11.7% | 2017-09-01 |
| CVE-2009-0174 EXP | Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF elem… | Patch early | 9.3 high | 11.7% | 2009-01-20 |
| CVE-2010-3631 EXP | Array index error in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execute arbitrary code via unspecifi… | Patch early | 9.3 high | 11.7% | 2010-10-06 |
| CVE-2000-0245 EXP | Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts. | Patch early | 10.0 high | 11.7% | 2000-03-27 |
| CVE-2006-3228 EXP | Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI)… | Patch early | 9.3 high | 11.7% | 2006-06-26 |
| CVE-2006-1206 EXP | Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attacker… | Patch early | 5.0 medium | 11.7% | 2006-03-14 |
| CVE-2005-2792 EXP | Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 11.7% | 2005-09-02 |
| CVE-2007-5604 EXP | Buffer overflow in the ExtractCab function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0… | Patch early | 7.5 high | 11.7% | 2008-06-04 |
| CVE-2010-2122 EXP | Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and… | Patch early | 6.8 medium | 11.7% | 2010-06-01 |
| CVE-1999-1520 EXP | A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, whi… | Patch early | 5.0 medium | 11.7% | 1999-05-11 |
| CVE-2008-0333 EXP | Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read a… | Patch early | 5.0 medium | 11.7% | 2008-01-17 |
| CVE-2012-4512 EXP | The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memo… | Patch early | 8.8 high | 11.7% | 2020-02-08 |
| CVE-2014-3976 EXP | Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a… | Patch early | 5.0 medium | 11.6% | 2014-06-05 |
| CVE-2001-0311 EXP | Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client. | Patch early | 4.6 medium | 11.6% | 2001-06-02 |
| CVE-2010-0050 EXP | Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (ap… | Patch early | 8.8 high | 11.6% | 2010-03-15 |
| CVE-2003-1090 EXP | Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title. | Patch early | 10.0 high | 11.6% | 2003-02-06 |
| CVE-2009-3859 EXP | Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cau… | Patch early | 9.3 high | 11.6% | 2009-11-04 |
| CVE-2002-0591 EXP | Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute co… | Patch early | 5.0 medium | 11.6% | 2002-06-18 |
| CVE-2009-1574 EXP | racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a… | Patch early | 5.0 medium | 11.6% | 2009-05-06 |
| CVE-2016-6566 EXP | The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software ver… | Patch early | 9.8 critical | 11.6% | 2018-07-13 |
| CVE-2008-4116 EXP | Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbit… | Patch early | 9.3 high | 11.6% | 2008-09-18 |
| CVE-2019-19731 EXP | Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE acti… | Patch early | 7.5 high | 11.6% | 2019-12-16 |
| CVE-2003-0129 EXP | Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that i… | Patch early | 5.0 medium | 11.6% | 2003-03-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt