CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
187,450 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-1327 EXP | Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u)… | Patch early | 9.3 high | 6% | 2009-04-17 |
| CVE-2008-3733 EXP | Stack-based buffer overflow in EO Video (eo-video) 1.36 allows remote attackers to cause a denial of service (application crash) or execute arbitrary… | Patch early | 9.3 high | 6% | 2008-08-20 |
| CVE-2009-4754 EXP | Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (… | Patch early | 9.3 high | 6% | 2010-03-29 |
| CVE-2007-6649 EXP | PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 6% | 2008-01-04 |
| CVE-2007-6657 EXP | PHP remote file inclusion vulnerability in source/includes/load_forum.php in Mihalism Multi Forum Host 3.0.x and earlier allows remote attackers to ex… | Patch early | 7.5 high | 6% | 2008-01-04 |
| CVE-2004-0345 EXP | Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name. | Patch early | 10.0 high | 6% | 2004-11-23 |
| CVE-2017-16716 EXP | A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands. | Patch early | 9.8 critical | 6% | 2018-01-05 |
| CVE-2008-7209 EXP | Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbi… | Patch early | 7.5 high | 6% | 2009-09-11 |
| CVE-2007-2667 EXP | Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execute arbitrary code via a long Lo… | Patch early | 9.3 high | 6% | 2007-05-14 |
| CVE-2008-2283 EXP | IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto… | Patch early | 9.3 high | 6% | 2008-05-18 |
| CVE-2016-4312 EXP | XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote auth… | Patch early | 7.5 high | 6% | 2017-02-17 |
| CVE-2002-0747 EXP | Buffer overflow in lsmcode in AIX 4.3.3. | Patch early | 10.0 high | 6% | 2002-08-12 |
| CVE-2018-5708 EXP | An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's pan… | Patch early | 8.0 high | 6% | 2018-03-30 |
| CVE-2018-19550 EXP | Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can c… | Patch early | 8.8 high | 6% | 2018-11-26 |
| CVE-2007-6542 EXP | PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attackers to execute arbitrary PHP c… | Patch early | 7.5 high | 6% | 2007-12-27 |
| CVE-2007-4962 EXP | Directory traversal vulnerability in WinImage 8.10 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a .. (… | Patch early | 9.3 high | 6% | 2007-09-18 |
| CVE-2020-16602 EXP | Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file c… | Patch early | 8.1 high | 6% | 2020-09-02 |
| CVE-2007-5583 EXP | Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" responses or device reboot) via a sequ… | Patch early | 7.8 high | 6% | 2007-12-18 |
| CVE-2003-0317 EXP | iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters. | Patch early | 7.5 high | 6% | 2003-12-31 |
| CVE-2013-4980 EXP | Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remo… | Patch early | 9.0 high | 6% | 2014-03-03 |
| CVE-2013-4981 EXP | Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remo… | Patch early | 9.0 high | 6% | 2014-03-03 |
| CVE-2010-4371 EXP | Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to the comment box… | Patch early | 9.3 high | 6% | 2010-12-02 |
| CVE-2018-7705 EXP | Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mail messages to arbitrary recipi… | Patch early | 8.1 high | 6% | 2018-03-15 |
| CVE-1999-1553 EXP | Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line. | Patch early | 10.0 high | 6% | 1999-05-01 |
| CVE-2000-0493 EXP | Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possibly execute arbitrary commands… | Patch early | 10.0 high | 6% | 2000-06-01 |
| CVE-2000-1026 EXP | Multiple buffer overflows in LBNL tcpdump allow remote attackers to execute arbitrary commands. | Patch early | 10.0 high | 6% | 2000-12-11 |
| CVE-2009-3664 EXP | Multiple directory traversal vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to include or execute arbitrary files via a .. (… | Patch early | 7.5 high | 6% | 2009-10-11 |
| CVE-2021-44653 EXP | Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due… | Patch early | 9.8 critical | 6% | 2021-12-15 |
| CVE-2021-44655 EXP | Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can… | Patch early | 9.8 critical | 6% | 2021-12-15 |
| CVE-2007-3365 EXP | MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive inf… | Patch early | 7.5 high | 6% | 2007-06-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt