CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,957 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-1879 EXP | The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured f… | Patch early | 7.5 high | 13.3% | 2016-01-29 |
| CVE-2011-2900 EXP | Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server… | Patch early | 7.5 high | 13.3% | 2011-08-05 |
| CVE-2020-5330 EXP | Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEd… | Patch early | 8.1 high | 13.3% | 2020-04-10 |
| CVE-2010-0442 EXP | The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of se… | Patch early | 6.5 medium | 13.3% | 2010-02-02 |
| CVE-2004-0722 EXP | Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allow… | Patch early | 10.0 high | 13.2% | 2004-08-18 |
| CVE-2006-0146 EXP | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) X… | Patch early | 7.5 high | 13.2% | 2006-01-09 |
| CVE-2010-4107 EXP | The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers… | Patch early | 7.8 high | 13.2% | 2010-11-17 |
| CVE-2009-2464 EXP | The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote atta… | Patch early | 10.0 high | 13.2% | 2009-07-22 |
| CVE-2018-14335 EXP | An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of th… | Patch early | 6.5 medium | 13.2% | 2018-07-24 |
| CVE-2018-7921 EXP | Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. Unauthenticated adjacent attackers may exploit this… | Patch early | 6.5 medium | 13.2% | 2018-09-12 |
| CVE-2009-0261 EXP | Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\D… | Patch early | 9.3 high | 13.2% | 2009-01-23 |
| CVE-2010-2036 EXP | Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbit… | Patch early | 7.5 high | 13.2% | 2010-05-25 |
| CVE-2004-0416 EXP | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execu… | Patch early | 10.0 high | 13.2% | 2004-08-06 |
| CVE-2007-3181 EXP | Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p… | Patch early | 10.0 high | 13.2% | 2007-06-12 |
| CVE-2002-1542 EXP | SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a… | Patch early | 5.0 medium | 13.2% | 2003-03-31 |
| CVE-2019-9792 EXP | The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value c… | Patch early | 9.8 critical | 13.2% | 2019-04-26 |
| CVE-2011-1471 EXP | Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU… | Patch early | 4.3 medium | 13.2% | 2011-03-20 |
| CVE-2005-2710 EXP | Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) ti… | Patch early | 5.1 medium | 13.2% | 2005-09-27 |
| CVE-2018-12604 EXP | GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log. | Patch early | 7.5 high | 13.2% | 2018-06-20 |
| CVE-2017-15663 EXP | In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER… | Patch early | 7.5 high | 13.2% | 2018-01-10 |
| CVE-2012-5614 EXP | Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a… | Patch early | 4.0 medium | 13.2% | 2012-12-03 |
| CVE-2008-2952 EXP | liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams th… | Patch early | 5.0 medium | 13.2% | 2008-07-01 |
| CVE-2016-8527 EXP | Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in… | Patch early | 6.1 medium | 13.2% | 2018-08-06 |
| CVE-2011-5127 EXP | Directory traversal vulnerability in Blue Coat Reporter 9.x before 9.2.4.13, 9.2.5.x before 9.2.5.1, and 9.3 before 9.3.1.2 on Windows allows remote a… | Patch early | 10.0 high | 13.2% | 2012-08-26 |
| CVE-2005-2310 EXP | Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file wi… | Patch early | 9.3 high | 13.1% | 2005-07-19 |
| CVE-2006-4965 EXP | Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTi… | Patch early | 5.0 medium | 13.1% | 2006-09-25 |
| CVE-2008-1801 EXP | Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly exe… | Patch early | 9.3 high | 13.1% | 2008-05-12 |
| CVE-2001-0197 EXP | Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands. | Patch early | 10.0 high | 13.1% | 2001-03-26 |
| CVE-2007-1645 EXP | Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on U… | Patch early | 10.0 high | 13.1% | 2007-03-24 |
| CVE-2008-0153 EXP | telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafte… | Patch early | 5.0 medium | 13.1% | 2008-01-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt