CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-0113 EXP | CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method,… | Patch early | 7.5 high | 77.8% | 2014-04-29 |
| CVE-2022-24734 EXP | MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctl… | Patch early | 7.2 high | 77.8% | 2022-03-09 |
| CVE-2017-1000117 EXP | A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that e… | Patch early | 8.8 high | 77.8% | 2017-10-05 |
| CVE-2010-0842 EXP | Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows rem… | Patch early | 7.5 high | 77.7% | 2010-04-01 |
| CVE-2008-2639 EXP | Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbit… | Patch early | 7.6 high | 77.7% | 2008-06-16 |
| CVE-2002-1123 EXP | Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execu… | Patch early | 7.5 high | 77.7% | 2002-09-24 |
| CVE-2018-10823 EXP | An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DW… | Patch early | 8.8 high | 77.7% | 2018-10-17 |
| CVE-2007-1748 EXP | Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP… | Patch early | 10.0 high | 77.7% | 2007-04-13 |
| CVE-2007-2446 EXP | Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via… | Patch early | 10.0 high | 77.7% | 2007-05-14 |
| CVE-2010-1549 EXP | Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary… | Patch early | 10.0 high | 77.6% | 2010-05-07 |
| CVE-2003-0714 EXP | The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directl… | Patch early | 7.5 high | 77.6% | 2003-11-17 |
| CVE-2013-0634 EXP | Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux,… | Patch early | 9.3 high | 77.6% | 2013-02-08 |
| CVE-2016-0709 EXP | Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated… | Patch early | 7.2 high | 77.5% | 2016-04-11 |
| CVE-2008-2499 EXP | Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8… | Patch early | 7.5 high | 77.5% | 2008-05-29 |
| CVE-2002-0079 EXP | Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to ca… | Patch early | 7.5 high | 77.3% | 2002-04-22 |
| CVE-2007-2508 EXP | Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote attackers to execute arbitrary… | Patch early | 10.0 high | 77.2% | 2007-05-08 |
| CVE-1999-1011 EXP | The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows… | Patch early | 10.0 high | 77.1% | 1999-07-19 |
| CVE-2020-10173 EXP | Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute… | Patch early | 8.8 high | 77.1% | 2020-03-05 |
| CVE-2017-12243 EXP | A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower… | Patch early | 7.8 high | 77.1% | 2017-11-02 |
| CVE-2013-1080 EXP | The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp… | Patch early | 10.0 high | 77% | 2013-03-29 |
| CVE-2018-15877 EXP | The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip parameter… | Patch early | 8.8 high | 77% | 2018-08-26 |
| CVE-2007-3236 EXP | PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 77% | 2007-06-15 |
| CVE-2011-5227 EXP | Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1.0.80 allows remote attackers… | Patch early | 10.0 high | 77% | 2012-10-25 |
| CVE-2018-1000049 EXP | Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API. The flaw can be exploite… | Patch early | 7.5 high | 76.9% | 2018-02-09 |
| CVE-2021-29156 EXP | ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-cha… | Patch early | 7.5 high | 76.8% | 2021-03-25 |
| CVE-2009-2685 EXP | Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers to execute arbitrary code via t… | Patch early | 10.0 high | 76.7% | 2009-11-06 |
| CVE-2010-3600 EXP | Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control… | Patch early | 7.5 high | 76.7% | 2011-01-19 |
| CVE-2007-5423 EXP | tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are proce… | Patch early | 7.5 high | 76.7% | 2007-10-12 |
| CVE-2006-5745 EXP | Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows,… | Patch early | 7.6 high | 76.6% | 2006-11-06 |
| CVE-2014-3936 EXP | Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-505 with fir… | Patch early | 10.0 high | 76.6% | 2014-06-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt