CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,041 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
187,284 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-8765 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web… | Patch early | 8.8 high | 6.9% | 2019-12-18 |
| CVE-2026-25895 EXP | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote att… | Patch early | 9.8 critical | 6.9% | 2026-02-09 |
| CVE-2004-1854 EXP | Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet. | Patch early | 7.5 high | 6.9% | 2004-03-24 |
| CVE-2004-2037 EXP | Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute a… | Patch early | 7.5 high | 6.9% | 2004-03-24 |
| CVE-2005-2767 EXP | Buffer overflow in LeapFTP allows remote attackers to execute arbitrary code via a long Host string in a Site Queue (.lsq) file. | Patch early | 7.5 high | 6.9% | 2005-09-02 |
| CVE-2010-3136 EXP | Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and co… | Patch early | 9.3 high | 6.9% | 2010-08-26 |
| CVE-2002-1463 EXP | Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5… | Patch early | 7.5 high | 6.9% | 2003-06-09 |
| CVE-2015-6639 EXP | The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted… | Patch early | 7.8 high | 6.9% | 2016-01-06 |
| CVE-2008-3285 EXP | The Filesys::SmbClientParser module 2.7 and earlier for Perl allows remote SMB servers to execute arbitrary code via a folder name containing shell me… | Patch early | 9.3 high | 6.9% | 2008-07-24 |
| CVE-2003-1240 EXP | PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in… | Patch early | 7.5 high | 6.9% | 2003-12-31 |
| CVE-2019-8624 EXP | An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacker may be able to leak memory. | Patch early | 7.5 high | 6.9% | 2019-12-18 |
| CVE-2015-7248 EXP | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password hashes by reading the cgi-bin/we… | Patch early | 7.5 high | 6.9% | 2015-12-30 |
| CVE-2009-3812 EXP | Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 a… | Patch early | 9.3 high | 6.9% | 2009-10-27 |
| CVE-2010-2932 EXP | Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument to t… | Patch early | 9.3 high | 6.9% | 2010-08-05 |
| CVE-2009-0812 EXP | Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions allows remote attackers to execut… | Patch early | 9.3 high | 6.9% | 2009-03-04 |
| CVE-2013-2642 EXP | Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to t… | Patch early | 9.3 high | 6.9% | 2014-03-18 |
| CVE-2018-6064 EXP | Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploi… | Patch early | 8.8 high | 6.9% | 2018-11-14 |
| CVE-2002-0098 EXP | Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long name field whe… | Patch early | 7.5 high | 6.9% | 2002-03-25 |
| CVE-2003-0766 EXP | Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious servers to execute arbitrary cod… | Patch early | 7.5 high | 6.9% | 2003-09-17 |
| CVE-2012-0242 EXP | Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers… | Patch early | 10.0 high | 6.9% | 2012-02-21 |
| CVE-2015-4683 EXP | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by levera… | Patch early | 9.8 critical | 6.9% | 2017-09-19 |
| CVE-2013-4103 EXP | Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input | Patch early | 9.8 critical | 6.9% | 2019-11-04 |
| CVE-2009-1670 EXP | user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vector… | Patch early | 7.5 high | 6.9% | 2009-05-18 |
| CVE-2003-0863 EXP | The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is n… | Patch early | 7.5 high | 6.9% | 2003-11-17 |
| CVE-2016-8580 EXP | PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PH… | Patch early | 9.8 critical | 6.9% | 2016-10-28 |
| CVE-2002-0730 EXP | Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields… | Patch early | 7.5 high | 6.9% | 2002-08-12 |
| CVE-2008-0747 EXP | Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute arbitrary code via a long URL… | Patch early | 9.3 high | 6.9% | 2008-02-13 |
| CVE-2009-1642 EXP | Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp… | Patch early | 9.3 high | 6.9% | 2009-05-15 |
| CVE-2009-4756 EXP | Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execute arbitrary code via a long s… | Patch early | 9.3 high | 6.9% | 2010-03-29 |
| CVE-2011-4529 EXP | Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow remote attackers to execute arbitrary code via a… | Patch early | 7.5 high | 6.9% | 2012-01-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt