CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,729 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
187,611 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-0528 EXP | The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various I… | Patch early | 9.0 high | 4.5% | 2007-01-26 |
| CVE-2009-0266 EXP | Stack-based buffer overflow in Triologic Media Player 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .… | Patch early | 9.3 high | 4.5% | 2009-01-26 |
| CVE-2009-3808 EXP | MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long str… | Patch early | 9.3 high | 4.5% | 2009-10-27 |
| CVE-2012-1002 EXP | SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid param… | Patch early | 10.0 high | 4.5% | 2012-02-08 |
| CVE-2019-7273 EXP | Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF). | Patch early | 8.8 high | 4.5% | 2019-07-01 |
| CVE-2015-4523 EXP | Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanis… | Patch early | 9.3 critical | 4.5% | 2017-09-11 |
| CVE-2023-31703 EXP | Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject a… | Patch early | 9.0 critical | 4.5% | 2023-05-17 |
| CVE-1999-0730 EXP | The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack. | Patch early | 10.0 high | 4.5% | 1999-06-12 |
| CVE-2003-1321 EXP | Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL… | Patch early | 7.5 high | 4.5% | 2003-12-31 |
| CVE-2003-1355 EXP | Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly… | Patch early | 7.5 high | 4.5% | 2003-12-31 |
| CVE-2013-0109 EXP | The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not properly handle exceptions, w… | Patch early | 7.2 high | 4.5% | 2013-04-08 |
| CVE-2004-0490 EXP | cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the… | Patch early | 7.2 high | 4.5% | 2004-08-18 |
| CVE-1999-0704 EXP | Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others. | Patch early | 9.3 high | 4.5% | 1999-09-16 |
| CVE-2016-9351 EXP | An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an attacker to upload a… | Patch early | 7.0 high | 4.5% | 2017-02-13 |
| CVE-2004-1836 EXP | SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the… | Patch early | 7.5 high | 4.4% | 2004-12-31 |
| CVE-2005-0047 EXP | Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to e… | Patch early | 7.2 high | 4.4% | 2005-05-02 |
| CVE-2019-8591 EXP | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A… | Patch early | 7.1 high | 4.4% | 2019-12-18 |
| CVE-2019-19363 EXP | An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation.… | Patch early | 7.8 high | 4.4% | 2020-01-24 |
| CVE-2004-1165 EXP | Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP… | Patch early | 7.5 high | 4.4% | 2005-01-10 |
| CVE-2014-8681 EXP | SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.6.x before 0.5.6.1025 Beta a… | Patch early | 7.5 high | 4.4% | 2014-11-21 |
| CVE-2008-5284 EXP | The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other versions before 5.0.52, Air Mars… | Patch early | 10.0 high | 4.4% | 2008-11-29 |
| CVE-2005-0958 EXP | Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to… | Patch early | 7.5 high | 4.4% | 2005-05-02 |
| CVE-2005-4622 EXP | Directory traversal vulnerability in eFileGo 3.01 allows remote attackers to execute arbitrary code, read arbitrary files, and upload arbitrary files… | Patch early | 7.5 high | 4.4% | 2005-12-31 |
| CVE-2006-2485 EXP | PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 allows remote attackers to execut… | Patch early | 7.5 high | 4.4% | 2006-05-19 |
| CVE-2007-2656 EXP | Stack-based buffer overflow in the Hewlett-Packard (HP) Magview ActiveX control in hpqvwocx.dll 1.0.0.309 allows remote attackers to cause a denial of… | Patch early | 7.8 high | 4.4% | 2007-05-14 |
| CVE-2017-13875 EXP | An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allo… | Patch early | 7.8 high | 4.4% | 2017-12-25 |
| CVE-2007-0756 EXP | Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large computer-name size value in a Serve… | Patch early | 7.8 high | 4.4% | 2007-02-06 |
| CVE-2004-0246 EXP | Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0… | Patch early | 10.0 high | 4.4% | 2004-11-23 |
| CVE-2009-3578 EXP | Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2… | Patch early | 9.3 high | 4.4% | 2009-11-24 |
| CVE-2008-4135 EXP | Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause a denial of service (device c… | Patch early | 7.8 high | 4.4% | 2008-09-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt