CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,984 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-3081 EXP | Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, A… | Patch early | 4.3 medium | 11.4% | 2015-05-13 |
| CVE-2007-5925 EXP | The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to… | Patch early | 4.0 medium | 11.4% | 2007-11-10 |
| CVE-2013-6877 EXP | Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote attackers to e… | Patch early | 9.3 high | 11.3% | 2013-12-19 |
| CVE-2016-1608 EXP | vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary comm… | Patch early | 8.8 high | 11.3% | 2016-08-01 |
| CVE-2010-4278 EXP | operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters… | Patch early | 9.0 high | 11.3% | 2010-12-02 |
| CVE-2003-0108 EXP | isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP pa… | Patch early | 5.0 medium | 11.3% | 2003-03-07 |
| CVE-2009-4018 EXP | The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and… | Patch early | 7.5 high | 11.3% | 2009-11-29 |
| CVE-2007-1421 EXP | Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root… | Patch early | 10.0 high | 11.3% | 2007-03-13 |
| CVE-2016-3716 EXP | The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image. | Patch early | 3.3 low | 11.3% | 2016-05-05 |
| CVE-2008-2595 EXP | Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact a… | Patch early | 5.0 medium | 11.3% | 2008-07-15 |
| CVE-2007-0243 EXP | Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and… | Patch early | 6.8 medium | 11.3% | 2007-01-17 |
| CVE-2007-0126 EXP | Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bytes in th… | Patch early | 9.3 high | 11.3% | 2007-01-09 |
| CVE-2010-3154 EXP | Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attackers, to execute arbitrary cod… | Patch early | 9.3 high | 11.3% | 2010-08-27 |
| CVE-2017-9430 EXP | Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified ot… | Patch early | 9.8 critical | 11.3% | 2017-06-05 |
| CVE-2010-0416 EXP | Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer al… | Patch early | 7.5 high | 11.3% | 2010-02-18 |
| CVE-2007-2583 EXP | The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a deni… | Patch early | 4.0 medium | 11.3% | 2007-05-10 |
| CVE-2020-25762 EXP | An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and… | Patch early | 9.1 critical | 11.3% | 2020-09-30 |
| CVE-2022-2552 EXP | The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server… | Patch early | 5.3 medium | 11.3% | 2022-08-22 |
| CVE-2015-7039 EXP | Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbit… | Patch early | 6.8 medium | 11.3% | 2015-12-11 |
| CVE-2017-17759 EXP | Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the confi… | Patch early | 9.8 critical | 11.3% | 2017-12-19 |
| CVE-2008-1461 EXP | Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line. NO… | Patch early | 7.6 high | 11.3% | 2008-03-24 |
| CVE-2006-4089 EXP | Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier allow remote attackers to cause a denial of service (application crash), or… | Patch early | 5.0 medium | 11.3% | 2006-08-11 |
| CVE-2010-3870 EXP | The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, whic… | Patch early | 6.8 medium | 11.3% | 2010-11-12 |
| CVE-2006-2223 EXP | RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authent… | Patch early | 5.0 medium | 11.3% | 2006-05-05 |
| CVE-2006-4920 EXP | Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to execute arbitrary PHP code via a… | Patch early | 7.5 high | 11.3% | 2006-09-21 |
| CVE-2017-2370 EXP | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. wa… | Patch early | 7.8 high | 11.3% | 2017-02-20 |
| CVE-2019-10009 EXP | A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploa… | Patch early | 6.5 medium | 11.3% | 2019-06-03 |
| CVE-2018-11511 EXP | The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' o… | Patch early | 9.8 critical | 11.3% | 2018-08-16 |
| CVE-2008-4547 EXP | Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows remote attackers to execute a… | Patch early | 9.3 high | 11.3% | 2008-10-14 |
| CVE-2000-0944 EXP | CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allow… | Patch early | 9.8 critical | 11.3% | 2000-12-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt