CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,152 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
25,087 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-2456 EXP | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Go… | Patch early | 9.3 high | 35.6% | 2015-08-15 |
| CVE-2015-2462 EXP | ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… | Patch early | 9.3 high | 35.6% | 2015-08-15 |
| CVE-2015-2464 EXP | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Go… | Patch early | 9.3 high | 35.6% | 2015-08-15 |
| CVE-2005-2119 EXP | The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regard… | Patch early | 5.0 medium | 35.5% | 2005-10-12 |
| CVE-2018-13109 EXP | All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to… | Patch early | 7.5 high | 35.5% | 2018-07-06 |
| CVE-2014-0038 EXP | The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privile… | Patch early | 6.9 medium | 35.5% | 2014-02-06 |
| CVE-1999-0015 EXP | Teardrop IP denial of service. | Patch early | 5.0 medium | 35.4% | 1997-12-16 |
| CVE-2022-0848 EXP | OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11. | Patch early | 9.8 critical | 35.4% | 2022-03-04 |
| CVE-2008-2908 EXP | Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attacker… | Patch early | 9.3 high | 35.4% | 2008-06-30 |
| CVE-2007-3435 EXP | Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote a… | Patch early | 9.3 high | 35.4% | 2007-06-27 |
| CVE-2007-0325 EXP | Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7… | Patch early | 9.3 high | 35.4% | 2007-02-20 |
| CVE-2020-24214 EXP | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP r… | Patch early | 9.8 critical | 35.4% | 2020-10-06 |
| CVE-2017-8225 EXP | On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentica… | Patch early | 9.8 critical | 35.4% | 2017-04-25 |
| CVE-2012-6081 EXP | Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in Mo… | Patch early | 6.0 medium | 35.3% | 2013-01-03 |
| CVE-2004-1104 EXP | Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page t… | Patch early | 7.5 high | 35.3% | 2004-12-31 |
| CVE-2015-6103 EXP | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Serv… | Patch early | 9.3 high | 35.3% | 2015-11-11 |
| CVE-2015-6104 EXP | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Serv… | Patch early | 9.3 high | 35.3% | 2015-11-11 |
| CVE-2017-0063 EXP | The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2; Windows Server 2008 SP2 and R2; and Windows 7 SP1; Windows… | Patch early | 6.5 medium | 35.3% | 2017-03-17 |
| CVE-2008-5492 EXP | Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX Control allows remote attacke… | Patch early | 9.3 high | 35.3% | 2008-12-12 |
| CVE-2020-35391 EXP | Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request… | Patch early | 9.6 critical | 35.2% | 2021-01-01 |
| CVE-2007-0348 EXP | Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.2… | Patch early | 9.3 high | 35.1% | 2007-03-21 |
| CVE-2008-1724 EXP | Stack-based buffer overflow in the IActiveXTransfer.FileTransfer method in the SecureTransport FileTransfer ActiveX control in vcst_en.dll 1.0.0.5 in… | Patch early | 9.3 high | 35.1% | 2008-04-11 |
| CVE-2010-0679 EXP | Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos ChemView 1.9.5.1 allow remote at… | Patch early | 9.3 high | 35.1% | 2010-02-22 |
| CVE-2009-2484 EXP | Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft W… | Patch early | 9.3 high | 35.1% | 2009-07-16 |
| CVE-2012-3753 EXP | Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (applicat… | Patch early | 9.3 high | 35.1% | 2012-11-09 |
| CVE-2009-3429 EXP | Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls pl… | Patch early | 9.3 high | 35% | 2009-09-25 |
| CVE-2021-43164 EXP | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the up… | Patch early | 8.8 high | 35% | 2022-05-04 |
| CVE-2010-2632 EXP | Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability. NOTE: the previ… | Patch early | 7.8 high | 35% | 2011-01-19 |
| CVE-2000-0380 EXP | The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a… | Patch early | 7.1 high | 35% | 2000-04-26 |
| CVE-2010-2103 EXP | Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1,… | Patch early | 4.3 medium | 34.9% | 2010-05-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt