CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-3729 EXP | DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office installed allows remote attackers to cause a denial of service (crash) via a la… | Patch early | 2.6 low | 20.6% | 2006-07-21 |
| CVE-2019-1127 EXP | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… | Patch early | 8.8 high | 20.6% | 2019-07-15 |
| CVE-2000-0983 EXP | Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null… | Patch early | 5.0 medium | 20.6% | 2000-12-19 |
| CVE-2014-9734 EXP | Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files… | Patch early | 5.0 medium | 20.6% | 2015-06-30 |
| CVE-2000-0967 EXP | PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error mess… | Patch early | 10.0 high | 20.6% | 2000-12-19 |
| CVE-2015-6018 EXP | The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary comm… | Patch early | 9.8 critical | 20.6% | 2015-12-31 |
| CVE-2008-5666 EXP | WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP se… | Patch early | 3.5 low | 20.6% | 2008-12-19 |
| CVE-2019-14312 EXP | Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This vulnerability allows a remote a… | Patch early | 6.5 medium | 20.6% | 2019-08-09 |
| CVE-2015-4664 EXP | An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands. | Patch early | 9.8 critical | 20.6% | 2018-06-18 |
| CVE-2009-4873 EXP | Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (serve… | Patch early | 10.0 high | 20.6% | 2010-05-26 |
| CVE-2011-1930 EXP | In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker t… | Patch early | 9.8 critical | 20.5% | 2019-11-14 |
| CVE-2006-3656 EXP | Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which… | Patch early | 2.6 low | 20.5% | 2006-07-18 |
| CVE-2016-7982 EXP | Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the syste… | Patch early | 7.5 high | 20.5% | 2017-01-18 |
| CVE-2002-2031 EXP | Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary files via a scr… | Patch early | 5.0 medium | 20.5% | 2002-12-31 |
| CVE-2019-14348 EXP | The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-york… | Patch early | 9.8 critical | 20.5% | 2019-08-05 |
| CVE-2004-0399 EXP | Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denia… | Patch early | 7.5 high | 20.5% | 2004-07-07 |
| CVE-2010-3967 EXP | Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via a Trojan horse DLL in the cur… | Patch early | 9.3 high | 20.5% | 2010-12-16 |
| CVE-2008-2949 EXP | Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String da… | Patch early | 6.8 medium | 20.5% | 2008-06-30 |
| CVE-2017-13156 EXP | An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID… | Patch early | 7.8 high | 20.5% | 2017-12-06 |
| CVE-2000-0676 EXP | Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a… | Patch early | 5.0 medium | 20.5% | 2000-10-20 |
| CVE-2016-4175 EXP | Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… | Patch early | 8.8 high | 20.5% | 2016-07-13 |
| CVE-2016-4179 EXP | Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… | Patch early | 8.8 high | 20.5% | 2016-07-13 |
| CVE-2008-0237 EXP | The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure Sav… | Patch early | 6.8 medium | 20.5% | 2008-01-11 |
| CVE-1999-0681 EXP | Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause… | Patch early | 5.0 medium | 20.5% | 2001-03-12 |
| CVE-2013-1598 EXP | A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, whi… | Patch early | 8.8 high | 20.5% | 2020-01-24 |
| CVE-2024-38200 EXP | Microsoft Office Spoofing Vulnerability | Patch early | 6.5 medium | 20.5% | 2024-08-12 |
| CVE-2016-4071 EXP | Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows r… | Patch early | 9.8 critical | 20.5% | 2016-05-20 |
| CVE-2014-1769 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-1774 EXP | Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web sit… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-1788 EXP | Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web sit… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt