CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,226 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
321,228 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-1465 EXP | Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via a long DNS query packet to UD… | Patch early | 10.0 high | 8.3% | 2007-03-24 |
| CVE-2010-1930 EXP | Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree par… | Patch early | 5.0 medium | 8.3% | 2010-06-28 |
| CVE-2005-3048 EXP | Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a… | Patch early | 6.4 medium | 8.3% | 2005-09-24 |
| CVE-2010-0278 EXP | A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allow… | Patch early | 4.3 medium | 8.3% | 2010-01-12 |
| CVE-2023-4114 EXP | A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing… | Patch early | 4.3 medium | 8.3% | 2023-08-03 |
| CVE-2006-1767 EXP | Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 8.3% | 2006-04-13 |
| CVE-2015-1362 EXP | Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary code via a long string in the ma… | Patch early | 7.5 high | 8.3% | 2015-01-27 |
| CVE-2005-0442 EXP | Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter. | Patch early | 5.0 medium | 8.3% | 2005-05-02 |
| CVE-2004-1934 EXP | PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter. | Patch early | 7.5 high | 8.3% | 2004-04-15 |
| CVE-2004-0128 EXP | PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitr… | Patch early | 7.5 high | 8.3% | 2004-03-03 |
| CVE-2009-2626 EXP | The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive… | Patch early | 6.4 medium | 8.3% | 2009-12-01 |
| CVE-2006-1100 EXP | Buffer overflow in the sgetstr function in shared/cube.h in Sauerbraten 2006_02_28 and earlier, as derived from the Cube engine, allows remote attacke… | Patch early | 7.5 high | 8.3% | 2006-03-09 |
| CVE-2004-1636 EXP | Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary… | Patch early | 10.0 high | 8.3% | 2004-10-26 |
| CVE-2018-15172 EXP | TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header. | Patch early | 7.5 high | 8.3% | 2018-08-15 |
| CVE-2008-7090 EXP | Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .… | Patch early | 7.8 high | 8.3% | 2009-08-26 |
| CVE-2019-9600 EXP | The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service v… | Patch early | 7.5 high | 8.3% | 2019-03-06 |
| CVE-2019-9601 EXP | The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many simultaneous /?Key=PhoneRequestA… | Patch early | 7.5 high | 8.3% | 2019-03-06 |
| CVE-2002-0893 EXP | Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com… | Patch early | 5.0 medium | 8.3% | 2002-10-04 |
| CVE-2010-2126 EXP | Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_ad… | Patch early | 7.5 high | 8.3% | 2010-06-01 |
| CVE-2006-2995 EXP | Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 8.3% | 2006-06-13 |
| CVE-2006-4051 EXP | PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 8.3% | 2006-08-10 |
| CVE-2006-4440 EXP | PHP remote file inclusion vulnerability in main.php in Ay System Solutions CMS 2.6 and earlier allows remote attackers to execute arbitrary PHP code v… | Patch early | 7.5 high | 8.3% | 2006-08-29 |
| CVE-2007-0820 EXP | Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 8.3% | 2007-02-07 |
| CVE-2016-3861 EXP | LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions… | Patch early | 7.8 high | 8.3% | 2016-09-11 |
| CVE-2019-8622 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watc… | Patch early | 8.8 high | 8.3% | 2019-12-18 |
| CVE-2019-8623 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watc… | Patch early | 8.8 high | 8.3% | 2019-12-18 |
| CVE-2002-0611 EXP | Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified dot dot) in the (1) head or (… | Patch early | 5.0 medium | 8.3% | 2002-06-18 |
| CVE-2005-4212 EXP | Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) se… | Patch early | 5.0 medium | 8.3% | 2005-12-14 |
| CVE-2018-5753 EXP | The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev… | Patch early | 6.5 medium | 8.3% | 2018-06-16 |
| CVE-2002-1451 EXP | Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (… | Patch early | 5.0 medium | 8.3% | 2002-08-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt