CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,331 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
25,087 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-4141 EXP | Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 30.5% | 2014-10-15 |
| CVE-2020-35749 EXP | Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress… | Patch early | 7.7 high | 30.5% | 2021-01-15 |
| CVE-2020-7384 EXP | Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbi… | Patch early | 7.0 high | 30.5% | 2020-10-29 |
| CVE-2021-25158 EXP | A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.… | Patch early | 5.9 medium | 30.5% | 2021-03-30 |
| CVE-2008-0392 EXP | Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .d… | Patch early | 9.3 high | 30.5% | 2008-01-23 |
| CVE-2025-24514 EXP | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to… | Patch early | 8.8 high | 30.5% | 2025-03-25 |
| CVE-2010-0926 EXP | The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote a… | Patch early | 3.5 low | 30.4% | 2010-03-10 |
| CVE-2011-0419 EXP | Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apach… | Patch early | 4.3 medium | 30.4% | 2011-05-16 |
| CVE-2007-1347 EXP | Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial… | Patch early | 7.1 high | 30.3% | 2007-03-08 |
| CVE-2015-0065 EXP | Microsoft Word 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office docume… | Patch early | 9.3 high | 30.3% | 2015-02-11 |
| CVE-2016-7182 EXP | The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2… | Patch early | 9.8 critical | 30.3% | 2016-10-14 |
| CVE-2015-2523 EXP | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Vie… | Patch early | 9.3 high | 30.3% | 2015-09-09 |
| CVE-2017-16524 EXP | Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authe… | Patch early | 8.8 high | 30.3% | 2017-11-06 |
| CVE-2018-19616 EXP | An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because acc… | Patch early | 8.1 high | 30.3% | 2018-12-26 |
| CVE-2014-1785 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 30.3% | 2014-06-11 |
| CVE-2010-0356 EXP | Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom Software Movie Player Pro SDK Ac… | Patch early | 9.3 high | 30.3% | 2010-01-18 |
| CVE-2007-3872 EXP | Multiple stack-based buffer overflows in the Shared Trace Service (OVTrace) service for HP OpenView Operations A.07.50 for Windows, and possibly earli… | Patch early | 6.8 medium | 30.3% | 2007-08-09 |
| CVE-2015-2432 EXP | ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… | Patch early | 9.3 high | 30.3% | 2015-08-15 |
| CVE-2020-5844 EXP | index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts… | Patch early | 7.2 high | 30.3% | 2020-03-16 |
| CVE-2018-10718 EXP | Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary c… | Patch early | 10.0 critical | 30.2% | 2018-05-03 |
| CVE-2025-50154 EXP | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network… | Patch early | 6.5 medium | 30.2% | 2025-08-12 |
| CVE-2015-4870 EXP | Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability… | Patch early | 4.0 medium | 30.1% | 2015-10-21 |
| CVE-2008-4295 EXP | Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection t… | Patch early | 5.4 medium | 30.1% | 2008-09-27 |
| CVE-2007-6331 EXP | Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe… | Patch early | 9.3 high | 30.1% | 2007-12-13 |
| CVE-2006-3014 EXP | Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an… | Patch early | 5.1 medium | 30.1% | 2006-06-22 |
| CVE-2017-1129 EXP | IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to ha… | Patch early | 6.5 medium | 30.1% | 2017-09-05 |
| CVE-2003-0665 EXP | Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 30.1% | 2003-10-20 |
| CVE-2003-0701 EXP | Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execut… | Patch early | 7.5 high | 30.1% | 2003-08-27 |
| CVE-2017-16995 EXP | The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption)… | Patch early | 7.8 high | 30.1% | 2017-12-27 |
| CVE-2015-0040 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 30% | 2015-02-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt