CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,164 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
321,935 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-1325 EXP | Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file. | Patch early | 9.3 high | 7.1% | 2009-04-17 |
| CVE-2009-1326 EXP | Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u)… | Patch early | 9.3 high | 7.1% | 2009-04-17 |
| CVE-2009-1328 EXP | Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m… | Patch early | 9.3 high | 7.1% | 2009-04-17 |
| CVE-1999-1020 EXP | The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access… | Patch early | 7.5 high | 7.1% | 1998-09-18 |
| CVE-2004-0520 EXP | Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the… | Patch early | 6.8 medium | 7.1% | 2004-08-18 |
| CVE-2008-3578 EXP | HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long irc:// U… | Patch early | 5.0 medium | 7.1% | 2008-08-10 |
| CVE-2018-12522 EXP | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing. | Patch early | 5.3 medium | 7.1% | 2018-06-18 |
| CVE-2018-12523 EXP | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing. | Patch early | 5.3 medium | 7.1% | 2018-06-18 |
| CVE-2018-12524 EXP | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing. | Patch early | 5.3 medium | 7.1% | 2018-06-18 |
| CVE-2018-12525 EXP | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing. | Patch early | 5.3 medium | 7.1% | 2018-06-18 |
| CVE-2003-0482 EXP | TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded code via a… | Patch early | 7.5 high | 7.1% | 2003-08-07 |
| CVE-2001-0697 EXP | NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command. | Patch early | 5.0 medium | 7.1% | 2001-09-20 |
| CVE-2001-0965 EXP | glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of… | Patch early | 5.0 medium | 7.1% | 2001-08-31 |
| CVE-2008-6971 EXP | The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues abou… | Patch early | 7.5 high | 7.1% | 2009-08-13 |
| CVE-2006-5177 EXP | The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecified vector… | Patch early | 9.3 high | 7.1% | 2006-10-10 |
| CVE-2007-6315 EXP | Group Chat in BarracudaDrive Web Server before 3.8 allows remote authenticated users to cause a denial of service (crash) via a HTTP request to /eh/ch… | Patch early | 4.0 medium | 7.1% | 2007-12-12 |
| CVE-2002-2200 EXP | Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP files via the "subpath" variabl… | Patch early | 7.5 high | 7.1% | 2002-12-31 |
| CVE-2006-1929 EXP | PHP remote file inclusion vulnerability in include/common.php in I-Rater Platinum allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 5.0 medium | 7.1% | 2006-04-20 |
| CVE-2007-2783 EXP | Unspecified vulnerability in Rational Soft Hidden Administrator 1.7 and earlier allows remote attackers to bypass authentication and execute arbitrary… | Patch early | 10.0 high | 7.1% | 2007-05-21 |
| CVE-2009-1839 EXP | Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote… | Patch early | 5.4 medium | 7.1% | 2009-06-12 |
| CVE-2002-1169 EXP | IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP requ… | Patch early | 5.0 medium | 7.1% | 2002-11-04 |
| CVE-2002-1236 EXP | The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of se… | Patch early | 5.0 medium | 7.1% | 2002-11-12 |
| CVE-2002-1906 EXP | The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending incomplete HTTP requ… | Patch early | 5.0 medium | 7.1% | 2002-12-31 |
| CVE-2003-1054 EXP | mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as pa… | Patch early | 5.0 medium | 7.1% | 2003-04-16 |
| CVE-2005-2904 EXP | Zebedee 2.4.1, when "allowed redirection port" is not set, allows remote attackers to cause a denial of service (application crash) via a zero in the… | Patch early | 5.0 medium | 7.1% | 2005-09-14 |
| CVE-2009-2698 EXP | The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users t… | Patch early | 7.8 high | 7.1% | 2009-08-27 |
| CVE-2006-2841 EXP | Multiple PHP remote file inclusion vulnerabilities in AssoCIateD (aka ACID) CMS 1.1.3 allow remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 7.1% | 2006-06-06 |
| CVE-2018-20166 EXP | A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishand… | Patch early | 8.8 high | 7.1% | 2019-01-02 |
| CVE-2000-0470 EXP | Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request. | Patch early | 7.5 high | 7.1% | 2000-06-01 |
| CVE-2008-4645 EXP | plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PH… | Patch early | 9.0 high | 7.1% | 2008-10-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt