CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,759 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-1661 EXP | Stack-based buffer overflow in DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 allows remote attackers to execute arbitrary… | Patch early | 10.0 high | 69% | 2008-06-04 |
| CVE-2001-0506 EXP | Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long fil… | Patch early | 7.2 high | 68.9% | 2001-09-20 |
| CVE-2013-2367 EXP | Multiple unspecified vulnerabilities in HP SiteScope 11.20 and 11.21, when SOAP is used, allow remote attackers to execute arbitrary code via unknown… | Patch early | 10.0 high | 68.9% | 2013-07-31 |
| CVE-2009-0695 EXP | hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access… | Patch early | 7.5 high | 68.9% | 2012-06-19 |
| CVE-2016-7286 EXP | The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… | Patch early | 7.5 high | 68.9% | 2016-12-20 |
| CVE-2016-7287 EXP | The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of servi… | Patch early | 7.5 high | 68.9% | 2016-12-20 |
| CVE-2019-10867 EXP | An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will m… | Patch early | 8.8 high | 68.9% | 2019-04-04 |
| CVE-2021-34621 EXP | A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it p… | Patch early | 9.8 critical | 68.9% | 2021-07-07 |
| CVE-2005-0308 EXP | Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export fu… | Patch early | 7.5 high | 68.9% | 2005-01-24 |
| CVE-2003-0050 EXP | parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 68.9% | 2003-03-07 |
| CVE-2013-3215 EXP | vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. | Patch early | 9.8 critical | 68.8% | 2020-01-29 |
| CVE-2007-0785 EXP | PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 68.8% | 2007-02-06 |
| CVE-2008-0960 EXP | SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Ses… | Patch early | 10.0 high | 68.8% | 2008-06-10 |
| CVE-2014-6039 EXP | ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000. | Patch early | 7.5 high | 68.8% | 2020-01-13 |
| CVE-2006-1255 EXP | Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (applicat… | Patch early | 10.0 high | 68.8% | 2006-03-19 |
| CVE-2007-2545 EXP | Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 68.8% | 2007-05-09 |
| CVE-2000-0886 EXP | IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating sys… | Patch early | 7.5 high | 68.7% | 2000-12-19 |
| CVE-2023-40028 EXP | Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload… | Patch early | 4.9 medium | 68.7% | 2023-08-15 |
| CVE-2017-8670 EXP | Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current… | Patch early | 7.5 high | 68.7% | 2017-08-08 |
| CVE-2012-5687 EXP | Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and… | Patch early | 7.8 high | 68.7% | 2012-11-01 |
| CVE-2007-4313 EXP | PHP remote file inclusion vulnerability in public_includes/pub_blocks/activecontent.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execut… | Patch early | 6.8 medium | 68.7% | 2007-08-13 |
| CVE-2004-0567 EXP | The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows S… | Patch early | 7.5 high | 68.7% | 2004-12-31 |
| CVE-2009-2990 EXP | Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitr… | Patch early | 9.3 high | 68.7% | 2009-10-19 |
| CVE-2007-3057 EXP | PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to exec… | Patch early | 6.8 medium | 68.7% | 2007-06-06 |
| CVE-2018-10594 EXP | Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS… | Patch early | 9.8 critical | 68.6% | 2018-06-26 |
| CVE-2015-7611 EXP | Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified ve… | Patch early | 8.1 high | 68.6% | 2016-06-07 |
| CVE-2009-2227 EXP | Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrary code via a crafted request t… | Patch early | 10.0 high | 68.6% | 2009-06-26 |
| CVE-2019-9053 EXP | An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-ba… | Patch early | 8.1 high | 68.6% | 2019-03-26 |
| CVE-2020-13951 EXP | Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. | Patch early | 7.5 high | 68.6% | 2020-09-30 |
| CVE-2018-11646 EXP | webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as use… | Patch early | 7.5 high | 68.6% | 2018-06-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt