CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,045 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1831 EXP | Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-e… | Patch early | 5.0 medium | 22.3% | 2002-12-31 |
| CVE-2014-6308 EXP | Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in… | Patch early | 5.0 medium | 22.3% | 2014-10-20 |
| CVE-2008-2469 EXP | Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitr… | Patch early | 10.0 high | 22.3% | 2008-10-23 |
| CVE-2006-7066 EXP | Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, d… | Patch early | 7.1 high | 22.2% | 2007-03-02 |
| CVE-2015-8660 EXP | The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local u… | Patch early | 6.7 medium | 22.2% | 2015-12-28 |
| CVE-2011-2131 EXP | Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a den… | Patch early | 9.3 high | 22.2% | 2011-08-11 |
| CVE-2008-0139 EXP | Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the… | Patch early | 6.8 medium | 22.2% | 2008-01-08 |
| CVE-2003-0899 EXP | Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '… | Patch early | 9.8 critical | 22.2% | 2003-11-03 |
| CVE-2008-0590 EXP | Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute… | Patch early | 9.0 high | 22.2% | 2008-02-05 |
| CVE-2001-0137 EXP | Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file n… | Patch early | 5.1 medium | 22.2% | 2001-03-12 |
| CVE-2011-1669 EXP | Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary fil… | Patch early | 5.0 medium | 22.2% | 2011-04-10 |
| CVE-2006-2444 EXP | The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) vi… | Patch early | 7.8 high | 22.1% | 2006-05-25 |
| CVE-2006-4494 EXP | Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiat… | Patch early | 7.5 high | 22.1% | 2006-08-31 |
| CVE-2006-7206 EXP | Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and… | Patch early | 7.8 high | 22.1% | 2007-06-22 |
| CVE-2008-6482 EXP | PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is e… | Patch early | 6.8 medium | 22.1% | 2009-03-18 |
| CVE-2002-1179 EXP | Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digi… | Patch early | 7.5 high | 22.1% | 2002-10-28 |
| CVE-2017-0120 EXP | Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive informatio… | Patch early | 4.3 medium | 22% | 2017-03-17 |
| CVE-2010-3325 EXP | Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in Cascading Style Sheets (CSS) documents, which allow… | Patch early | 4.3 medium | 22% | 2010-10-13 |
| CVE-2019-8016 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 22% | 2019-08-20 |
| CVE-2012-1858 EXP | The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does n… | Patch early | 4.3 medium | 22% | 2012-06-12 |
| CVE-2022-4510 EXP | A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesyste… | Patch early | 7.8 high | 22% | 2023-01-26 |
| CVE-2002-0386 EXP | The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash)… | Patch early | 5.0 medium | 22% | 2002-11-04 |
| CVE-2006-6296 EXP | The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and e… | Patch early | 6.1 medium | 22% | 2006-12-05 |
| CVE-2013-3846 EXP | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (m… | Patch early | 9.3 high | 22% | 2013-12-29 |
| CVE-2017-3623 EXP | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are affected see n… | Patch early | 10.0 critical | 22% | 2017-04-24 |
| CVE-2001-1244 EXP | Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment s… | Patch early | 5.0 medium | 22% | 2001-07-07 |
| CVE-2003-0282 EXP | Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, w… | Patch early | 2.6 low | 22% | 2003-06-16 |
| CVE-2018-19246 EXP | PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their… | Patch early | 7.5 high | 22% | 2018-11-13 |
| CVE-2003-0666 EXP | Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters… | Patch early | 7.5 high | 21.9% | 2003-10-20 |
| CVE-2020-10884 EXP | This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750… | Patch early | 8.8 high | 21.9% | 2020-03-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt