CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,955 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
12,664 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1048 EXP | HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the… | Patch early | 7.5 high | 13.5% | 2002-10-04 |
| CVE-2019-8565 EXP | A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able… | Patch early | 7.0 high | 13.5% | 2019-12-18 |
| CVE-2008-0964 EXP | Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote… | Patch early | 9.3 high | 13.5% | 2008-08-08 |
| CVE-2010-0972 EXP | Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrar… | Patch early | 7.5 high | 13.5% | 2010-03-16 |
| CVE-2018-6383 EXP | Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extensio… | Patch early | 8.8 high | 13.5% | 2018-01-29 |
| CVE-2019-6967 EXP | AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF. | Patch early | 8.8 high | 13.5% | 2019-03-21 |
| CVE-2006-1618 EXP | Format string vulnerability in the (1) Con_message and (2) conPrintf functions in con_main.c in Doomsday engine 1.8.6 allows remote attackers to execu… | Patch early | 7.5 high | 13.5% | 2006-04-05 |
| CVE-2019-9581 EXP | phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP… | Patch early | 8.8 high | 13.5% | 2019-03-06 |
| CVE-2017-6444 EXP | The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows r… | Patch early | 7.5 high | 13.5% | 2017-03-12 |
| CVE-2000-0941 EXP | Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter. | Patch early | 10.0 high | 13.5% | 2000-12-19 |
| CVE-2001-0021 EXP | MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter. | Patch early | 10.0 high | 13.5% | 2001-02-16 |
| CVE-2007-1536 EXP | Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file th… | Patch early | 9.3 high | 13.5% | 2007-03-20 |
| CVE-2017-3064 EXP | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline. Successful exploi… | Patch early | 7.8 high | 13.5% | 2017-04-12 |
| CVE-2018-0709 EXP | Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitra… | Patch early | 8.8 high | 13.4% | 2018-07-17 |
| CVE-2008-3956 EXP | orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute… | Patch early | 9.3 high | 13.4% | 2008-09-11 |
| CVE-2008-3732 EXP | Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (applicat… | Patch early | 9.3 high | 13.4% | 2008-08-20 |
| CVE-2011-1944 EXP | Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers… | Patch early | 9.3 high | 13.4% | 2011-09-02 |
| CVE-2019-17424 EXP | A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewa… | Patch early | 7.8 high | 13.4% | 2019-10-22 |
| CVE-2016-2278 EXP | Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administ… | Patch early | 7.2 high | 13.4% | 2016-03-02 |
| CVE-2013-4787 EXP | Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrar… | Patch early | 9.3 high | 13.4% | 2013-07-09 |
| CVE-2019-10863 EXP | A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file wit… | Patch early | 7.2 high | 13.4% | 2019-04-04 |
| CVE-2019-8043 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 7.5 high | 13.4% | 2019-08-20 |
| CVE-2011-2628 EXP | Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service… | Patch early | 10.0 high | 13.4% | 2011-07-01 |
| CVE-2017-10661 EXP | Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption… | Patch early | 7.0 high | 13.4% | 2017-08-19 |
| CVE-2010-1653 EXP | Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! allows remote attackers to incl… | Patch early | 7.5 high | 13.4% | 2010-05-03 |
| CVE-2018-1000001 EXP | In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading t… | Patch early | 7.8 high | 13.4% | 2018-01-31 |
| CVE-2004-1437 EXP | Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attackers to execute arbitrary code. | Patch early | 7.5 high | 13.4% | 2004-12-31 |
| CVE-2010-1470 EXP | Directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly hav… | Patch early | 7.5 high | 13.4% | 2010-04-19 |
| CVE-2010-1472 EXP | Directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files v… | Patch early | 7.5 high | 13.4% | 2010-04-19 |
| CVE-2012-4329 EXP | The Samsung D6000 TV and possibly other products allow remote attackers to cause a denial of service (continuous restart) via a crafted controller nam… | Patch early | 7.8 high | 13.3% | 2012-08-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt