CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,143 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
186,071 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-0371 EXP | Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to exec… | Patch early | 7.5 high | 54.4% | 2002-07-03 |
| CVE-2007-3040 EXP | Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a… | Patch early | 9.3 high | 54.4% | 2007-09-12 |
| CVE-2021-36356 EXP | KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary e… | Patch early | 9.8 critical | 54.4% | 2021-08-31 |
| CVE-2011-0027 EXP | Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation f… | Patch early | 9.3 high | 54.4% | 2011-01-12 |
| CVE-2019-6453 EXP | mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc://… | Patch early | 8.1 high | 54.3% | 2019-02-18 |
| CVE-2018-18326 EXP | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue e… | Patch early | 7.5 high | 54.3% | 2019-07-03 |
| CVE-1999-0661 EXP | A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) u… | Patch early | 10.0 high | 54.2% | 1999-01-01 |
| CVE-2018-5347 EXP | Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because… | Patch early | 9.8 critical | 54.2% | 2018-01-12 |
| CVE-2017-8487 EXP | Windows OLE in Windows XP and Windows Server 2003 allows an attacker to execute code when a victim opens a specially crafted file or program aka "Wind… | Patch early | 7.8 high | 54.1% | 2017-06-15 |
| CVE-2001-0800 EXP | lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. | Patch early | 10.0 high | 54.1% | 2001-12-06 |
| CVE-2019-19609 EXP | The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel,… | Patch early | 7.2 high | 54.1% | 2019-12-05 |
| CVE-2010-1663 EXP | The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy… | Patch early | 10.0 high | 54.1% | 2010-05-03 |
| CVE-2006-2379 EXP | Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers t… | Patch early | 9.3 high | 54.1% | 2006-06-13 |
| CVE-2008-6221 EXP | PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remote attacke… | Patch early | 7.5 high | 54% | 2009-02-20 |
| CVE-2008-1610 EXP | Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service or execute arbitrary code via a… | Patch early | 7.5 high | 53.9% | 2008-04-01 |
| CVE-2025-27007 EXP | Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a… | Patch early | 9.8 critical | 53.9% | 2025-05-01 |
| CVE-2007-3896 EXP | The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attack… | Patch early | 9.3 high | 53.8% | 2007-10-11 |
| CVE-2008-0550 EXP | Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a c… | Patch early | 10.0 high | 53.8% | 2008-02-01 |
| CVE-2018-8734 EXP | SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL comm… | Patch early | 9.8 critical | 53.8% | 2018-04-18 |
| CVE-2016-5676 EXP | cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows r… | Patch early | 7.5 high | 53.7% | 2016-08-31 |
| CVE-2008-4255 EXP | Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0,… | Patch early | 9.3 high | 53.7% | 2008-12-10 |
| CVE-2006-3459 EXP | Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-depe… | Patch early | 7.5 high | 53.7% | 2006-08-03 |
| CVE-2017-7310 EXP | A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskS… | Patch early | 7.8 high | 53.7% | 2017-03-29 |
| CVE-2019-6441 EXP | An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The passw… | Patch early | 9.8 critical | 53.6% | 2019-03-21 |
| CVE-2017-17932 EXP | A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute ar… | Patch early | 9.8 critical | 53.6% | 2017-12-28 |
| CVE-2023-27823 EXP | An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. | Patch early | 9.8 critical | 53.6% | 2023-05-12 |
| CVE-2019-19844 EXP | Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing… | Patch early | 9.8 critical | 53.6% | 2019-12-18 |
| CVE-2002-1254 EXP | Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other… | Patch early | 7.5 high | 53.5% | 2002-12-11 |
| CVE-2023-29689 EXP | PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vuln… | Patch early | 9.8 critical | 53.5% | 2023-08-04 |
| CVE-2021-23017 EXP | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte… | Patch early | 7.7 high | 53.5% | 2021-06-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt