CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,522 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-0005 EXP | Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long arg… | Patch early | 10.0 high | 15.5% | 2002-01-31 |
| CVE-2005-3560 EXP | Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1,… | Patch early | 7.5 high | 15.5% | 2005-11-16 |
| CVE-2018-1041 EXP | A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could… | Patch early | 7.5 high | 15.5% | 2018-02-15 |
| CVE-2006-4059 EXP | Multiple PHP remote file inclusion vulnerabilities in USOLVED NEWSolved Lite 1.9.2, and possibly earlier, allow remote attackers to execute arbitrary… | Patch early | 7.5 high | 15.5% | 2006-08-10 |
| CVE-2007-4646 EXP | Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably… | Patch early | 10.0 high | 15.5% | 2007-08-31 |
| CVE-2009-3373 EXP | Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote at… | Patch early | 10.0 high | 15.5% | 2009-10-29 |
| CVE-2007-2666 EXP | Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attac… | Patch early | 7.6 high | 15.5% | 2007-05-14 |
| CVE-2008-2138 EXP | Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/po… | Patch early | 5.0 medium | 15.5% | 2008-05-12 |
| CVE-2014-6437 EXP | Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors in… | Patch early | 9.8 critical | 15.5% | 2018-01-12 |
| CVE-2019-1151 EXP | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succes… | Patch early | 8.8 high | 15.5% | 2019-08-14 |
| CVE-2002-1368 EXP | Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary c… | Patch early | 7.5 high | 15.5% | 2002-12-26 |
| CVE-2003-0101 EXP | miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (C… | Patch early | 10.0 high | 15.5% | 2003-03-03 |
| CVE-2004-1423 EXP | Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Of… | Patch early | 7.5 high | 15.5% | 2004-12-31 |
| CVE-2004-0935 EXP | Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and gl… | Patch early | 7.5 high | 15.5% | 2005-01-27 |
| CVE-2007-0103 EXP | The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including d… | Patch early | 6.8 medium | 15.5% | 2007-01-09 |
| CVE-2014-2069 EXP | Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname in the file parameter to File… | Patch early | 7.5 high | 15.4% | 2018-04-16 |
| CVE-2008-0175 EXP | Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote attackers to execute arbitrary c… | Patch early | 7.5 high | 15.4% | 2008-01-29 |
| CVE-2020-28977 EXP | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and e… | Patch early | 5.3 medium | 15.4% | 2020-11-30 |
| CVE-2020-28978 EXP | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and e… | Patch early | 5.3 medium | 15.4% | 2020-11-30 |
| CVE-2003-0870 EXP | Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped charact… | Patch early | 7.5 high | 15.4% | 2003-11-17 |
| CVE-2014-1778 EXP | Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, ak… | Patch early | 6.8 medium | 15.4% | 2014-06-11 |
| CVE-2003-0845 EXP | Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remo… | Patch early | 7.5 high | 15.4% | 2003-11-17 |
| CVE-2007-2237 EXP | Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO fil… | Patch early | 5.5 medium | 15.4% | 2007-06-06 |
| CVE-2012-3575 EXP | Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrary code b… | Patch early | 10.0 high | 15.4% | 2012-06-16 |
| CVE-2018-8463 EXP | An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser,… | Patch early | 7.4 high | 15.4% | 2018-09-13 |
| CVE-2018-8469 EXP | An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser,… | Patch early | 7.4 high | 15.4% | 2018-09-13 |
| CVE-2025-34040 EXP | An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters ar… | Patch early | — | 15.4% | 2025-06-24 |
| CVE-2017-9414 EXP | Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentica… | Patch early | 8.8 high | 15.4% | 2018-02-05 |
| CVE-2022-35583 EXP | wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial… | Patch early | 9.8 critical | 15.4% | 2022-08-22 |
| CVE-2008-2841 EXP | Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary… | Patch early | 6.8 medium | 15.4% | 2008-06-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt