CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-0361 EXP | Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to… | Patch early | 10.0 high | 80.4% | 2010-01-20 |
| CVE-2008-0244 EXP | SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo a… | Patch early | 10.0 high | 80.3% | 2008-01-12 |
| CVE-2003-0349 EXP | Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Ser… | Patch early | 7.5 high | 80.3% | 2003-07-24 |
| CVE-2007-5365 EXP | Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based… | Patch early | 7.2 high | 80.3% | 2007-10-11 |
| CVE-2014-3829 EXP | displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitra… | Patch early | 10.0 high | 80.2% | 2014-10-23 |
| CVE-2014-9583 EXP | common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other router… | Patch early | 10.0 high | 80.2% | 2015-01-08 |
| CVE-2002-1359 EXP | Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service… | Patch early | 10.0 high | 80.2% | 2002-12-23 |
| CVE-2015-7387 EXP | ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL com… | Patch early | 7.5 high | 80.2% | 2015-09-28 |
| CVE-2019-0567 EXP | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scri… | Patch early | 7.5 high | 80.1% | 2019-01-08 |
| CVE-2019-11600 EXP | A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id… | Patch early | 8.1 high | 80% | 2019-05-13 |
| CVE-2013-6829 EXP | admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parame… | Patch early | 7.5 high | 79.9% | 2013-11-20 |
| CVE-2021-42362 EXP | The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src… | Patch early | 8.8 high | 79.8% | 2021-11-17 |
| CVE-2004-1080 EXP | The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbit… | Patch early | 10.0 high | 79.8% | 2005-01-10 |
| CVE-2006-4777 EXP | Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, o… | Patch early | 7.6 high | 79.8% | 2006-09-14 |
| CVE-2014-7866 EXP | Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0… | Patch early | 7.5 high | 79.8% | 2014-12-10 |
| CVE-2006-5143 EXP | Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightS… | Patch early | 7.5 high | 79.5% | 2006-10-10 |
| CVE-2006-5276 EXP | Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote… | Patch early | 10.0 high | 79.4% | 2007-02-20 |
| CVE-2008-5499 EXP | Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers to execute arbitrary code via… | Patch early | 9.3 high | 79.4% | 2008-12-18 |
| CVE-2007-0449 EXP | Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Deskt… | Patch early | 10.0 high | 79.4% | 2007-01-23 |
| CVE-2014-4872 EXP | BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary… | Patch early | 7.5 high | 79.3% | 2014-10-10 |
| CVE-2005-1921 EXP | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earli… | Patch early | 7.5 high | 79.1% | 2005-07-05 |
| CVE-2016-8740 EXP | The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-h… | Patch early | 7.5 high | 79.1% | 2016-12-05 |
| CVE-2023-32707 EXP | In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who hold… | Patch early | 8.8 high | 79% | 2023-06-01 |
| CVE-2009-3548 EXP | The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for th… | Patch early | 7.5 high | 79% | 2009-11-12 |
| CVE-2018-17553 EXP | An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authent… | Patch early | 8.8 high | 79% | 2018-10-03 |
| CVE-2009-3843 EXP | HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduc… | Patch early | 10.0 high | 79% | 2009-11-24 |
| CVE-2015-7709 EXP | The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execu… | Patch early | 10.0 high | 79% | 2015-10-05 |
| CVE-2018-0769 EXP | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… | Patch early | 7.5 high | 79% | 2018-01-04 |
| CVE-2006-4691 EXP | Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allo… | Patch early | 10.0 high | 78.9% | 2006-11-14 |
| CVE-2017-17692 EXP | Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript cod… | Patch early | 7.5 high | 78.8% | 2017-12-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt