CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,286 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
187,395 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-5281 EXP | Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a long DELE command. | Patch early | 10.0 high | 6.4% | 2008-11-29 |
| CVE-2008-5071 EXP | Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated users to execute arbitrary PHP c… | Patch early | 9.0 high | 6.4% | 2008-11-14 |
| CVE-2014-0997 EXP | WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung SM-T310, Android… | Patch early | 7.5 high | 6.4% | 2017-09-26 |
| CVE-2001-0198 EXP | Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBE… | Patch early | 7.6 high | 6.4% | 2001-05-03 |
| CVE-2006-4234 EXP | PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP co… | Patch early | 7.5 high | 6.4% | 2006-08-18 |
| CVE-2009-3586 EXP | Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code… | Patch early | 7.5 high | 6.4% | 2009-12-08 |
| CVE-2002-2219 EXP | chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) f… | Patch early | 7.5 high | 6.4% | 2002-12-31 |
| CVE-2003-1091 EXP | Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and… | Patch early | 7.5 high | 6.4% | 2003-12-31 |
| CVE-2006-7052 EXP | Multiple PHP remote file inclusion vulnerabilities in DotWidget For Articles (dotwidgeta) 0.2 allow remote attackers to execute arbitrary code via a U… | Patch early | 10.0 high | 6.4% | 2007-02-24 |
| CVE-2018-4089 EXP | An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected.… | Patch early | 8.8 high | 6.4% | 2018-04-03 |
| CVE-2017-15643 EXP | An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. IKARUS AV for Windows uses cleart… | Patch early | 7.4 high | 6.4% | 2017-10-19 |
| CVE-2014-2921 EXP | The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an objec… | Patch early | 7.5 high | 6.4% | 2014-04-21 |
| CVE-2025-14558 EXP | The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is passe… | Patch early | 7.2 high | 6.4% | 2026-03-09 |
| CVE-2023-0744 EXP | Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4. | Patch early | 9.8 critical | 6.4% | 2023-02-08 |
| CVE-2007-1851 EXP | Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to include and execute arbitrary l… | Patch early | 7.5 high | 6.4% | 2007-04-03 |
| CVE-2023-36348 EXP | POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter. | Patch early | 8.8 high | 6.4% | 2023-06-23 |
| CVE-2011-5172 EXP | Stack-based buffer overflow in StoryBoard Quick 6 Build 3786, and possibly StoryBoard Artist and StoryBoard Studio, allows remote attackers to execute… | Patch early | 9.3 high | 6.4% | 2012-09-15 |
| CVE-2008-0632 EXP | Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitrary code by uploading a file w… | Patch early | 9.3 high | 6.4% | 2008-02-06 |
| CVE-2008-6955 EXP | mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configurati… | Patch early | 7.5 high | 6.4% | 2009-08-12 |
| CVE-2008-2338 EXP | Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts i… | Patch early | 7.5 high | 6.4% | 2008-05-19 |
| CVE-2008-5897 EXP | CodeAvalanche FreeWallpaper stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2008-5898 EXP | CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download th… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2008-5899 EXP | CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2008-5900 EXP | CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… | Patch early | 7.5 high | 6.4% | 2009-01-12 |
| CVE-2007-6668 EXP | admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestric… | Patch early | 7.5 high | 6.4% | 2008-01-08 |
| CVE-2008-6752 EXP | adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords,… | Patch early | 7.5 high | 6.3% | 2009-04-24 |
| CVE-2010-5194 EXP | Stack-based buffer overflow in the Image2PDF function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx) in Viscom Image Viewer CP Pro… | Patch early | 9.3 high | 6.3% | 2012-08-31 |
| CVE-2015-8612 EXP | The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users to gain privileges via the dh… | Patch early | 8.4 high | 6.3% | 2016-01-08 |
| CVE-2021-45814 EXP | Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account… | Patch early | 9.8 critical | 6.3% | 2021-12-28 |
| CVE-2008-7240 EXP | Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote attackers to include and e… | Patch early | 7.5 high | 6.3% | 2009-09-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt