CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,355 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-0542 EXP | mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users… | Patch early | 7.2 high | 1.5% | 2002-07-03 |
| CVE-2015-3643 EXP | usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and be… | Patch early | 7.8 high | 1.5% | 2017-09-28 |
| CVE-2015-6009 EXP | Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 1.5% | 2015-09-28 |
| CVE-2017-14961 EXP | In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8300… | Patch early | 7.8 high | 1.5% | 2017-11-15 |
| CVE-2025-55912 EXP | An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload a… | Patch early | 7.3 high | 1.5% | 2025-09-18 |
| CVE-2013-5656 EXP | FuzeZip 1.0.0.131625 has a Local Buffer Overflow vulnerability | Patch early | 7.8 high | 1.5% | 2020-01-07 |
| CVE-2016-7084 EXP | tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual pr… | Patch early | 7.8 high | 1.5% | 2016-12-29 |
| CVE-2012-1665 EXP | Multiple SQL injection vulnerabilities in the admin panel in osCMax before 2.5.1 allow (1) remote attackers to execute arbitrary SQL commands via the… | Patch early | 7.5 high | 1.5% | 2015-05-20 |
| CVE-2012-4951 EXP | Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to exe… | Patch early | 7.5 high | 1.5% | 2012-11-15 |
| CVE-2006-1327 EXP | SQL injection vulnerability in reg.php in SoftBB 0.1 allows remote attackers to execute arbitrary SQL commands via the mail parameter. | Patch early | 7.5 high | 1.5% | 2006-03-21 |
| CVE-2006-1708 EXP | SQL injection vulnerability in member.php in Clansys 1.1 allows remote attackers to execute arbitrary SQL commands via the showid parameter in the mem… | Patch early | 7.5 high | 1.5% | 2006-04-11 |
| CVE-2018-0437 EXP | A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administra… | Patch early | 7.8 high | 1.5% | 2018-10-05 |
| CVE-2017-16237 EXP | In Vir.IT eXplorer Anti-Virus before 8.5.42, the driver file (VIAGLT64.SYS) contains an Arbitrary Write vulnerability because of not validating input… | Patch early | 7.8 high | 1.5% | 2017-11-03 |
| CVE-2024-4007 EXP | Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly co… | Patch early | 8.8 high | 1.5% | 2024-07-01 |
| CVE-2016-7387 EXP | For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… | Patch early | 7.8 high | 1.5% | 2016-11-08 |
| CVE-2006-5675 EXP | Multiple unspecified vulnerabilities in Pentaho Business Intelligence (BI) Suite before 1.2 RC3 (1.2.0.470-RC3) have unknown impact and attack vectors… | Patch early | 10.0 high | 1.5% | 2006-11-03 |
| CVE-2003-0089 EXP | Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG envir… | Patch early | 7.2 high | 1.5% | 2003-12-15 |
| CVE-2007-6125 EXP | SQL injection vulnerability in search_form.php in Softbiz Freelancers Script 1 allows remote attackers to execute arbitrary SQL commands via the sb_pr… | Patch early | 7.5 high | 1.5% | 2007-11-26 |
| CVE-2012-5244 EXP | Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) return,… | Patch early | 7.5 high | 1.5% | 2014-10-20 |
| CVE-2016-7083 EXP | VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enab… | Patch early | 7.8 high | 1.5% | 2016-12-29 |
| CVE-2016-7385 EXP | For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability… | Patch early | 7.8 high | 1.5% | 2016-11-08 |
| CVE-2018-18629 EXP | An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux. An untrusted search path vulnerability in the keybas… | Patch early | 7.8 high | 1.5% | 2018-12-20 |
| CVE-2008-0383 EXP | Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute arbitrary SQL commands via (1)… | Patch early | 7.5 high | 1.5% | 2008-01-22 |
| CVE-2018-14533 EXP | read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /var is a symlink to /tmp. | Patch early | 7.8 high | 1.5% | 2018-07-31 |
| CVE-2017-1297 EXP | IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by… | Patch early | 7.3 high | 1.5% | 2017-06-27 |
| CVE-2006-3065 EXP | SQL injection vulnerability in engine/shards/blog.php in blur6ex 0.3.462 allows remote attackers to execute arbitrary SQL commands via the ID paramete… | Patch early | 7.5 high | 1.5% | 2006-06-19 |
| CVE-2000-1028 EXP | Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument. | Patch early | 7.2 high | 1.5% | 2000-12-11 |
| CVE-2004-0510 EXP | Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code,… | Patch early | 7.2 high | 1.5% | 2004-12-23 |
| CVE-2019-18915 EXP | A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability ma… | Patch early | 7.8 high | 1.5% | 2020-02-13 |
| CVE-2018-10576 EXP | An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Ac… | Patch early | 7.8 high | 1.5% | 2018-04-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt