CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,587 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-1080 EXP | The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbit… | Patch early | 10.0 high | 79.8% | 2005-01-10 |
| CVE-2006-4777 EXP | Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, o… | Patch early | 7.6 high | 79.8% | 2006-09-14 |
| CVE-2012-1495 EXP | install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter. | Patch early | 9.8 critical | 79.8% | 2020-01-27 |
| CVE-2014-7866 EXP | Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0… | Patch early | 7.5 high | 79.8% | 2014-12-10 |
| CVE-2016-6563 EXP | Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnera… | Patch early | 9.8 critical | 79.7% | 2018-07-13 |
| CVE-2011-4858 EXP | Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trig… | Patch early | 5.0 medium | 79.7% | 2012-01-05 |
| CVE-2016-2555 EXP | SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the sea… | Patch early | 9.8 critical | 79.6% | 2017-04-13 |
| CVE-2006-5143 EXP | Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightS… | Patch early | 7.5 high | 79.5% | 2006-10-10 |
| CVE-2018-10662 EXP | An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. | Patch early | 9.8 critical | 79.5% | 2018-06-26 |
| CVE-2006-5614 EXP | Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to caus… | Patch early | 2.6 low | 79.5% | 2006-10-31 |
| CVE-2023-2745 EXP | WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated at… | Patch early | 5.4 medium | 79.5% | 2023-05-17 |
| CVE-2006-5276 EXP | Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote… | Patch early | 10.0 high | 79.4% | 2007-02-20 |
| CVE-2008-5499 EXP | Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers to execute arbitrary code via… | Patch early | 9.3 high | 79.4% | 2008-12-18 |
| CVE-2007-0449 EXP | Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Deskt… | Patch early | 10.0 high | 79.4% | 2007-01-23 |
| CVE-2014-4872 EXP | BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary… | Patch early | 7.5 high | 79.3% | 2014-10-10 |
| CVE-2005-1921 EXP | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earli… | Patch early | 7.5 high | 79.1% | 2005-07-05 |
| CVE-2016-8740 EXP | The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-h… | Patch early | 7.5 high | 79.1% | 2016-12-05 |
| CVE-2023-32707 EXP | In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who hold… | Patch early | 8.8 high | 79% | 2023-06-01 |
| CVE-2009-3548 EXP | The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for th… | Patch early | 7.5 high | 79% | 2009-11-12 |
| CVE-2018-17553 EXP | An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authent… | Patch early | 8.8 high | 79% | 2018-10-03 |
| CVE-2009-3843 EXP | HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduc… | Patch early | 10.0 high | 79% | 2009-11-24 |
| CVE-2015-7709 EXP | The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execu… | Patch early | 10.0 high | 79% | 2015-10-05 |
| CVE-2018-0769 EXP | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… | Patch early | 7.5 high | 79% | 2018-01-04 |
| CVE-2014-6034 EXP | Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8… | Patch early | 5.0 medium | 79% | 2014-12-04 |
| CVE-2006-4691 EXP | Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allo… | Patch early | 10.0 high | 78.9% | 2006-11-14 |
| CVE-2019-1622 EXP | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to r… | Patch early | 5.3 medium | 78.9% | 2019-06-27 |
| CVE-2017-17692 EXP | Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript cod… | Patch early | 7.5 high | 78.8% | 2017-12-21 |
| CVE-2018-7890 EXP | A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredenti… | Patch early | 9.8 critical | 78.8% | 2018-03-08 |
| CVE-2021-24931 EXP | The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_exp… | Patch early | 9.8 critical | 78.8% | 2021-12-06 |
| CVE-2013-2730 EXP | Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code v… | Patch early | 10.0 high | 78.8% | 2013-05-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt