CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,084 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0491 EXP | Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of se… | Patch early | 10.0 high | 17.8% | 2000-05-24 |
| CVE-2021-31159 EXP | Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Pas… | Patch early | 5.3 medium | 17.8% | 2021-06-16 |
| CVE-2008-3957 EXP | The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrary files onto a client system v… | Patch early | 9.3 high | 17.8% | 2008-09-11 |
| CVE-2005-3634 EXP | frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to ar… | Patch early | 5.0 medium | 17.8% | 2005-11-16 |
| CVE-2002-0153 EXP | Internet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke local AppleScripts within a specific HTML element, ak… | Patch early | 7.5 high | 17.7% | 2002-04-22 |
| CVE-2016-3644 EXP | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syman… | Patch early | 8.4 high | 17.7% | 2016-06-30 |
| CVE-2016-3646 EXP | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syman… | Patch early | 8.4 high | 17.7% | 2016-06-30 |
| CVE-2016-9949 EXP | An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it… | Patch early | 7.8 high | 17.7% | 2016-12-17 |
| CVE-2009-4273 EXP | stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line arguments in a… | Patch early | 10.0 high | 17.7% | 2010-01-26 |
| CVE-2016-1768 EXP | QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… | Patch early | 7.8 high | 17.7% | 2016-03-24 |
| CVE-2025-7769 EXP | Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allow… | Patch early | — | 17.7% | 2025-08-06 |
| CVE-2017-5177 EXP | A Stack Buffer Overflow issue was discovered in VIPA Controls WinPLC7 5.0.45.5921 and prior. A stack-based buffer overflow vulnerability has been iden… | Patch early | 7.5 high | 17.7% | 2017-05-19 |
| CVE-2014-1677 EXP | Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information. | Patch early | 7.5 high | 17.7% | 2017-04-03 |
| CVE-2018-19627 EXP | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer bou… | Patch early | 7.5 high | 17.7% | 2018-11-29 |
| CVE-2012-4992 EXP | Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1)… | Patch early | 9.0 high | 17.7% | 2012-09-19 |
| CVE-2011-4041 EXP | webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an… | Patch early | 10.0 high | 17.7% | 2012-02-06 |
| CVE-2015-8257 EXP | The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app par… | Patch early | 8.8 high | 17.7% | 2017-05-02 |
| CVE-1999-0877 EXP | Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME. | Patch early | 4.3 medium | 17.7% | 1999-10-01 |
| CVE-2001-1489 EXP | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large numbe… | Patch early | 5.0 medium | 17.7% | 2001-12-31 |
| CVE-2007-0463 EXP | Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash)… | Patch early | 5.0 medium | 17.7% | 2007-01-29 |
| CVE-2006-1010 EXP | Buffer overflow in socket/request.c in CrossFire before 1.9.0, when oldsocketmode is enabled, allows remote attackers to cause a denial of service (se… | Patch early | 6.4 medium | 17.6% | 2006-03-06 |
| CVE-2021-24274 EXP | The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribu… | Patch early | 6.1 medium | 17.6% | 2021-05-05 |
| CVE-2008-5282 EXP | Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF… | Patch early | 10.0 high | 17.6% | 2008-11-29 |
| CVE-2002-1705 EXP | Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{… | Patch early | 5.0 medium | 17.6% | 2002-12-31 |
| CVE-2015-2279 EXP | cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows remote attackers to execute a… | Patch early | 9.8 critical | 17.6% | 2017-07-25 |
| CVE-2019-9083 EXP | SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued. | Patch early | 9.8 critical | 17.6% | 2019-03-21 |
| CVE-2000-0347 EXP | Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name. | Patch early | 5.0 medium | 17.6% | 2000-05-02 |
| CVE-2006-6659 EXP | The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Ex… | Patch early | 5.0 medium | 17.6% | 2006-12-20 |
| CVE-2001-0150 EXP | Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote a… | Patch early | 5.1 medium | 17.6% | 2001-06-02 |
| CVE-2008-4493 EXP | Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to… | Patch early | 6.8 medium | 17.6% | 2008-10-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt