CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,218 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
25,087 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-36355 EXP | TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows… | Patch early | 9.9 critical | 31.7% | 2023-06-22 |
| CVE-2019-6714 EXP | An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unaut… | Patch early | 9.8 critical | 31.7% | 2019-03-21 |
| CVE-2007-2244 EXP | Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code… | Patch early | 9.3 high | 31.7% | 2007-04-25 |
| CVE-2012-5613 EXP | MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who s… | Patch early | 6.0 medium | 31.7% | 2012-12-03 |
| CVE-2013-3120 EXP | Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 31.6% | 2013-06-12 |
| CVE-2015-8048 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… | Patch early | 10.0 high | 31.6% | 2015-12-10 |
| CVE-2015-8410 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… | Patch early | 10.0 high | 31.6% | 2015-12-10 |
| CVE-2015-8411 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… | Patch early | 10.0 high | 31.6% | 2015-12-10 |
| CVE-2015-8412 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… | Patch early | 10.0 high | 31.6% | 2015-12-10 |
| CVE-2015-8413 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… | Patch early | 10.0 high | 31.6% | 2015-12-10 |
| CVE-2008-4728 EXP | Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard… | Patch early | 9.3 high | 31.6% | 2008-10-24 |
| CVE-2001-0010 EXP | Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges. | Patch early | 10.0 high | 31.6% | 2001-02-12 |
| CVE-2009-4656 EXP | Stack-based buffer overflow in E-Soft DJ Studio Pro 4.2 including 4.2.2.7.5, and 5.x including 5.1.4.3.1, allows user-assisted remote attackers to cau… | Patch early | 9.3 high | 31.6% | 2010-03-03 |
| CVE-2013-4467 EXP | Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier a… | Patch early | 6.5 medium | 31.6% | 2014-03-11 |
| CVE-2001-0663 EXP | Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol… | Patch early | 5.0 medium | 31.6% | 2001-12-06 |
| CVE-2012-2176 EXP | Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote att… | Patch early | 9.3 high | 31.6% | 2012-05-25 |
| CVE-2009-0880 EXP | Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and exec… | Patch early | 6.8 medium | 31.6% | 2009-03-12 |
| CVE-2012-3807 EXP | Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution. | Patch early | 9.8 critical | 31.6% | 2020-01-09 |
| CVE-2007-3764 EXP | The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, A… | Patch early | 5.0 medium | 31.5% | 2007-07-18 |
| CVE-2013-3482 EXP | Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers… | Patch early | 9.3 high | 31.5% | 2014-01-19 |
| CVE-2008-5178 EXP | Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overla… | Patch early | 9.3 high | 31.5% | 2008-11-20 |
| CVE-2008-0376 EXP | PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 6.8 medium | 31.5% | 2008-01-22 |
| CVE-2015-2525 EXP | Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and… | Patch early | 7.2 high | 31.5% | 2015-09-09 |
| CVE-2013-2088 EXP | contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary c… | Patch early | 7.1 high | 31.5% | 2013-07-31 |
| CVE-2020-23972 EXP | In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can als… | Patch early | 7.5 high | 31.4% | 2020-08-27 |
| CVE-2012-3137 EXP | The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain… | Patch early | 6.4 medium | 31.4% | 2012-09-21 |
| CVE-2013-5912 EXP | VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in t… | Patch early | 10.0 high | 31.4% | 2013-11-28 |
| CVE-2019-9041 EXP | An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting i… | Patch early | 7.2 high | 31.4% | 2019-02-23 |
| CVE-2014-1683 EXP | The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is… | Patch early | 6.8 medium | 31.4% | 2014-01-29 |
| CVE-1999-0678 EXP | A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the e… | Patch early | 5.0 medium | 31.4% | 1999-01-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt