CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
187,450 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-4633 EXP | Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1)… | Patch early | 9.8 critical | 6.1% | 2018-10-18 |
| CVE-2009-3428 EXP | Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted .wav file. | Patch early | 9.3 high | 6.1% | 2009-09-25 |
| CVE-2017-2369 EXP | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. Th… | Patch early | 8.8 high | 6.1% | 2017-02-20 |
| CVE-2017-2373 EXP | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. Th… | Patch early | 8.8 high | 6.1% | 2017-02-20 |
| CVE-2013-0526 EXP | ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remo… | Patch early | 8.5 high | 6.1% | 2013-08-21 |
| CVE-2007-2865 EXP | Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the ser… | Patch early | 9.3 high | 6.1% | 2007-05-25 |
| CVE-2014-100014 EXP | Multiple stack-based buffer overflows in pdmwService.exe in SolidWorks Workgroup PDM 2014 SP2 allow remote attackers to execute arbitrary code via a l… | Patch early | 7.5 high | 6.1% | 2015-01-13 |
| CVE-2009-0423 EXP | Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include and execute arbitrary local file… | Patch early | 7.5 high | 6.1% | 2009-02-05 |
| CVE-2009-1445 EXP | Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary files via directory traversal sequ… | Patch early | 7.5 high | 6.1% | 2009-04-27 |
| CVE-2005-0636 EXP | Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via… | Patch early | 10.0 high | 6.1% | 2005-03-02 |
| CVE-2017-17593 EXP | Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/. | Patch early | 7.5 high | 6.1% | 2017-12-13 |
| CVE-2009-3188 EXP | PHP remote file inclusion vulnerability in save.php in phpSANE 0.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the file_save… | Patch early | 7.5 high | 6.1% | 2009-09-15 |
| CVE-2023-26918 EXP | Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as… | Patch early | 9.8 critical | 6.1% | 2023-04-14 |
| CVE-2010-4613 EXP | Multiple directory traversal vulnerabilities in Hycus CMS 1.0.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot)… | Patch early | 7.5 high | 6.1% | 2010-12-29 |
| CVE-2014-2579 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication o… | Patch early | 7.6 high | 6% | 2014-04-25 |
| CVE-2017-2514 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" co… | Patch early | 8.8 high | 6% | 2017-05-22 |
| CVE-2009-3810 EXP | Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code v… | Patch early | 9.3 high | 6% | 2009-10-27 |
| CVE-2022-35513 EXP | The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage. | Patch early | 7.5 high | 6% | 2022-09-07 |
| CVE-1999-0268 EXP | MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. | Patch early | 10.0 high | 6% | 1999-01-01 |
| CVE-2021-28379 EXP | web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different ori… | Patch early | 8.8 high | 6% | 2021-03-15 |
| CVE-2015-7570 EXP | Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open… | Patch early | 7.2 high | 6% | 2017-04-24 |
| CVE-2008-3209 EXP | Heap-based buffer overflow in the OpenGifFile function in BiGif.dll in Black Ice Document Imaging SDK 10.95 allows remote attackers to execute arbitra… | Patch early | 9.3 high | 6% | 2008-07-18 |
| CVE-2008-4548 EXP | Stack-based buffer overflow in the PTZCamPanelCtrl ActiveX control (CamPanel.dll) in RTS Sentry 2.1.0.2 allows remote attackers to execute arbitrary c… | Patch early | 9.3 high | 6% | 2008-10-14 |
| CVE-2017-17874 EXP | Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can mak… | Patch early | 8.8 high | 6% | 2017-12-27 |
| CVE-2006-2225 EXP | Buffer overflow in XM Easy Personal FTP Server 4.3 and earlier allows remote attackers to execute arbitrary code, probably via a USER command with a l… | Patch early | 7.5 high | 6% | 2006-05-05 |
| CVE-2006-2408 EXP | Multiple buffer overflows in Raydium before SVN revision 310 allow remote attackers to execute arbitrary code via a large packet when logged via (1) t… | Patch early | 7.5 high | 6% | 2006-05-16 |
| CVE-2001-0173 EXP | Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execut… | Patch early | 10.0 high | 6% | 2001-05-03 |
| CVE-2011-5006 EXP | Stack-based buffer overflow in QQPlayer 3.2.845 allows remote attackers to execute arbitrary code via a crafted PnSize value in a MOV file. | Patch early | 9.3 high | 6% | 2011-12-25 |
| CVE-2004-0241 EXP | X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php. | Patch early | 10.0 high | 6% | 2004-11-23 |
| CVE-2009-1071 EXP | Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a cra… | Patch early | 9.3 high | 6% | 2009-03-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt