CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,546 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-5257 EXP | Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allow… | Patch early | 10.0 high | 15.2% | 2007-10-06 |
| CVE-2022-1565 EXP | The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions… | Patch early | 7.2 high | 15.2% | 2022-07-18 |
| CVE-2006-5864 EXP | Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to exec… | Patch early | 5.1 medium | 15.2% | 2006-11-11 |
| CVE-2023-0777 EXP | Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4. | Patch early | 9.8 critical | 15.2% | 2023-02-10 |
| CVE-2018-11311 EXP | A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server o… | Patch early | 9.1 critical | 15.2% | 2018-05-20 |
| CVE-2010-4328 EXP | Multiple stack-based buffer overflows in opt/novell/iprint/bin/ipsmd in Novell iPrint for Linux Open Enterprise Server 2 SP2 and SP3 allow remote atta… | Patch early | 7.5 high | 15.2% | 2011-02-19 |
| CVE-2001-0746 EXP | Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and pos… | Patch early | 10.0 high | 15.2% | 2001-10-18 |
| CVE-2008-3790 EXP | The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (C… | Patch early | 5.0 medium | 15.2% | 2008-08-27 |
| CVE-2007-1383 EXP | Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this co… | Patch early | 9.8 critical | 15.2% | 2007-03-10 |
| CVE-2014-4334 EXP | Stack-based buffer overflow in Ubisoft Rayman Legends before 1.3.140380 allows remote attackers to execute arbitrary code via a long string in the "se… | Patch early | 7.5 high | 15.2% | 2014-06-19 |
| CVE-2003-1236 EXP | Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via forma… | Patch early | 10.0 high | 15.2% | 2003-12-31 |
| CVE-2017-17672 EXP | In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circums… | Patch early | 9.8 critical | 15.2% | 2017-12-14 |
| CVE-2017-9380 EXP | OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context… | Patch early | 8.8 high | 15.2% | 2017-06-02 |
| CVE-2006-4253 EXP | Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arb… | Patch early | 7.6 high | 15.2% | 2006-08-21 |
| CVE-2017-5991 EXP | An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NU… | Patch early | 7.5 high | 15.2% | 2017-02-15 |
| CVE-2014-2674 EXP | Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attackers to read arbitrary files via… | Patch early | 7.5 high | 15.2% | 2018-03-19 |
| CVE-2011-3499 EXP | Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execut… | Patch early | 10.0 high | 15.2% | 2011-09-16 |
| CVE-2013-6924 EXP | Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip… | Patch early | 9.8 critical | 15.2% | 2017-10-11 |
| CVE-2014-5091 EXP | A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user… | Patch early | 9.8 critical | 15.2% | 2020-02-07 |
| CVE-2018-18322 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_… | Patch early | 9.8 critical | 15.1% | 2018-10-15 |
| CVE-2015-2780 EXP | Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an execut… | Patch early | 9.8 critical | 15.1% | 2017-10-16 |
| CVE-2007-6682 EXP | Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary c… | Patch early | 7.5 high | 15.1% | 2008-01-17 |
| CVE-2012-4409 EXP | Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute ar… | Patch early | 6.8 medium | 15.1% | 2012-11-21 |
| CVE-2019-8024 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 15.1% | 2019-08-20 |
| CVE-2017-8644 EXP | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that… | Patch early | 4.3 medium | 15.1% | 2017-08-08 |
| CVE-2016-5228 EXP | Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11997 and 9.… | Patch early | 9.8 critical | 15.1% | 2016-07-03 |
| CVE-2019-1019 EXP | A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerabi… | Patch early | 8.5 high | 15.1% | 2019-06-12 |
| CVE-2018-2636 EXP | Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security). Supported versions that are af… | Patch early | 8.1 high | 15.1% | 2018-01-18 |
| CVE-2010-4645 EXP | strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to… | Patch early | 5.0 medium | 15.1% | 2011-01-11 |
| CVE-2010-1533 EXP | Directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (d… | Patch early | 7.5 high | 15.1% | 2010-04-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt