CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,692 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-12276 EXP | A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attac… | Patch early | 7.5 high | 57.1% | 2019-06-05 |
| CVE-2005-1009 EXP | Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length… | Patch early | 10.0 high | 57% | 2005-05-02 |
| CVE-2022-28080 EXP | Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter. | Patch early | 8.8 high | 56.9% | 2022-05-05 |
| CVE-2008-0320 EXP | Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly… | Patch early | 9.3 high | 56.9% | 2008-04-17 |
| CVE-2016-3222 EXP | Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microso… | Patch early | 8.8 high | 56.8% | 2016-06-16 |
| CVE-2015-4553 EXP | A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell. | Patch early | 8.8 high | 56.7% | 2020-01-06 |
| CVE-2014-0782 EXP | Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 an… | Patch early | 8.3 high | 56.7% | 2014-05-16 |
| CVE-2017-6527 EXP | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticate… | Patch early | 7.5 high | 56.6% | 2017-03-09 |
| CVE-2004-0842 EXP | Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memo… | Patch early | 7.5 high | 56.6% | 2004-12-23 |
| CVE-2008-1087 EXP | Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to e… | Patch early | 9.3 high | 56.6% | 2008-04-08 |
| CVE-2015-3080 EXP | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.4… | Patch early | 10.0 high | 56.6% | 2015-05-13 |
| CVE-2015-4074 EXP | Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot do… | Patch early | 7.5 high | 56.5% | 2017-09-20 |
| CVE-2003-0558 EXP | Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request. | Patch early | 7.5 high | 56.5% | 2003-08-18 |
| CVE-2006-3086 EXP | Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attacker… | Patch early | 9.3 high | 56.5% | 2006-06-19 |
| CVE-2007-4607 EXP | Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61… | Patch early | 9.3 high | 56.4% | 2007-08-31 |
| CVE-2010-4742 EXP | Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows remote attackers to execute arb… | Patch early | 10.0 high | 56.4% | 2011-02-18 |
| CVE-2011-2882 EXP | Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0… | Patch early | 9.3 high | 56.4% | 2011-07-21 |
| CVE-2007-4809 EXP | Multiple PHP remote file inclusion vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 allow remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 56.4% | 2007-09-11 |
| CVE-2008-0659 EXP | Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx… | Patch early | 10.0 high | 56.3% | 2008-02-08 |
| CVE-2007-3456 EXP | Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1)… | Patch early | 9.3 high | 56.3% | 2007-07-11 |
| CVE-2008-4008 EXP | Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7… | Patch early | 10.0 high | 56.3% | 2008-10-14 |
| CVE-2006-6707 EXP | Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (a… | Patch early | 7.5 high | 56.2% | 2006-12-23 |
| CVE-2007-1579 EXP | Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command. | Patch early | 10.0 high | 56.2% | 2007-03-21 |
| CVE-2007-0046 EXP | Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbi… | Patch early | 7.5 high | 55.9% | 2007-01-03 |
| CVE-2008-3704 EXP | Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Vis… | Patch early | 9.3 high | 55.9% | 2008-08-18 |
| CVE-2006-3280 EXP | Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an objec… | Patch early | 7.5 high | 55.9% | 2006-06-28 |
| CVE-2017-8635 EXP | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… | Patch early | 7.5 high | 55.9% | 2017-08-08 |
| CVE-2019-14322 EXP | In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames. | Patch early | 7.5 high | 55.8% | 2019-07-28 |
| CVE-2011-3494 EXP | WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a… | Patch early | 10.0 high | 55.8% | 2011-09-16 |
| CVE-2013-0025 EXP | Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers a… | Patch early | 9.3 high | 55.8% | 2013-02-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt