CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,729 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
403,729 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2540 EXP | Multiple PHP remote file inclusion vulnerabilities in PMECMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the con… | Patch early | 7.5 high | 9.3% | 2007-05-09 |
| CVE-2011-5233 EXP | Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pi… | Patch early | 4.3 medium | 9.3% | 2012-10-25 |
| CVE-2010-2004 EXP | Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assisted remote attackers to execute… | Patch early | 9.3 high | 9.3% | 2010-05-20 |
| CVE-2007-4391 EXP | Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application cras… | Patch early | 9.3 high | 9.3% | 2007-08-17 |
| CVE-2022-26149 EXP | MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Upl… | Patch early | 7.2 high | 9.3% | 2022-02-26 |
| CVE-2008-6922 EXP | Multiple stack-based buffer overflows in CMailCOM.dll in CMailServer 5.4.6 allow remote attackers to execute arbitrary code via a long argument to the… | Patch early | 9.3 high | 9.3% | 2009-08-10 |
| CVE-2019-14347 EXP | Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/… | Patch early | 8.8 high | 9.3% | 2019-08-06 |
| CVE-2007-5305 EXP | Multiple PHP remote file inclusion vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) co… | Patch early | 7.5 high | 9.3% | 2007-10-09 |
| CVE-2015-3704 EXP | runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows att… | Patch early | 9.3 high | 9.3% | 2015-07-03 |
| CVE-2014-1631 EXP | Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php. | Patch early | 7.5 high | 9.3% | 2018-01-31 |
| CVE-2018-9038 EXP | Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request. | Patch early | 6.5 medium | 9.3% | 2018-04-10 |
| CVE-2009-0833 EXP | Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute arbitrary code via a playlist… | Patch early | 9.3 high | 9.3% | 2009-03-05 |
| CVE-2008-2910 EXP | Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll 6.0.18.1 and mvtextout.dll, in… | Patch early | 9.3 high | 9.3% | 2008-06-30 |
| CVE-2016-1328 EXP | goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long h_sortWireless parameter… | Patch early | 7.5 high | 9.3% | 2016-07-03 |
| CVE-2016-1336 EXP | goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long LanguageSelect parameter,… | Patch early | 7.5 high | 9.3% | 2016-07-03 |
| CVE-2012-5878 EXP | Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in… | Patch early | 9.8 critical | 9.3% | 2020-01-03 |
| CVE-2015-4062 EXP | SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to exec… | Patch early | 6.5 medium | 9.3% | 2015-05-27 |
| CVE-2008-4682 EXP | wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a malformed Tamos CommView captu… | Patch early | 5.0 medium | 9.3% | 2008-10-22 |
| CVE-2010-4301 EXP | epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (i… | Patch early | 5.0 medium | 9.3% | 2010-11-26 |
| CVE-2017-2464 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 8.8 high | 9.3% | 2017-04-02 |
| CVE-2020-11457 EXP | pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user. | Patch early | 5.4 medium | 9.3% | 2020-04-01 |
| CVE-2012-4242 EXP | Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 9.3% | 2012-10-01 |
| CVE-2008-4610 EXP | MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2)… | Patch early | 5.0 medium | 9.3% | 2008-10-20 |
| CVE-2013-2560 EXP | Directory traversal vulnerability in the web interface on Foscam devices with firmware before 11.37.2.49 allows remote attackers to read arbitrary fil… | Patch early | 7.8 high | 9.3% | 2013-03-15 |
| CVE-2000-1132 EXP | DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" variable. | Patch early | 6.4 medium | 9.3% | 2001-01-09 |
| CVE-2019-13292 EXP | A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Th… | Patch early | 9.8 critical | 9.3% | 2019-07-04 |
| CVE-2009-4219 EXP | Stack-based buffer overflow in the MYACTIVEX.MyActiveXCtrl.1 ActiveX control in MyActiveX.ocx 1.4.8.0 in Haihaisoft Universal Player allows remote att… | Patch early | 9.3 high | 9.3% | 2009-12-07 |
| CVE-2024-45440 EXP | core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of… | Patch early | 5.3 medium | 9.3% | 2024-08-29 |
| CVE-2007-0635 EXP | Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config… | Patch early | 7.5 high | 9.3% | 2007-01-31 |
| CVE-2011-0018 EXP | The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execute arbitr… | Patch early | 9.0 high | 9.3% | 2011-01-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt