CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,917 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-0517 EXP | Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows remote attackers to cause a de… | Patch early | 9.3 high | 40.5% | 2011-01-20 |
| CVE-2015-3118 EXP | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… | Patch early | 10.0 high | 40.4% | 2015-07-09 |
| CVE-2007-3147 EXP | Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute ar… | Patch early | 9.3 high | 40.4% | 2007-06-11 |
| CVE-2014-0980 EXP | Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI file. | Patch early | 9.3 high | 40.4% | 2014-02-11 |
| CVE-2013-0136 EXP | Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to… | Patch early | 8.5 high | 40.3% | 2013-06-01 |
| CVE-2007-4475 EXP | Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers to… | Patch early | 9.3 high | 40.3% | 2009-04-01 |
| CVE-2006-2383 EXP | Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpec… | Patch early | 9.3 high | 40.3% | 2006-06-13 |
| CVE-2015-6000 EXP | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.ph… | Patch early | 8.8 high | 40.2% | 2020-02-06 |
| CVE-2012-3579 EXP | Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain p… | Patch early | 7.9 high | 40.2% | 2012-08-29 |
| CVE-2009-2011 EXP | Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not r… | Patch early | 9.3 high | 40.2% | 2009-06-16 |
| CVE-2013-1710 EXP | The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.… | Patch early | 10.0 high | 40.1% | 2013-08-07 |
| CVE-2014-8586 EXP | SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands vi… | Patch early | 7.5 high | 40.1% | 2014-11-04 |
| CVE-2009-1025 EXP | PHP remote file inclusion vulnerability in linkadmin.php in Beerwin PHPLinkAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 40.1% | 2009-03-20 |
| CVE-2007-5243 EXP | Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers t… | Patch early | 9.3 high | 40.1% | 2007-10-06 |
| CVE-2009-2754 EXP | Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe),… | Patch early | 10.0 high | 40.1% | 2010-03-05 |
| CVE-2014-2928 EXP | The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through… | Patch early | 7.1 high | 40.1% | 2014-05-12 |
| CVE-2002-1973 EXP | Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in… | Patch early | 7.5 high | 40% | 2002-12-31 |
| CVE-2009-0187 EXP | Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote attackers to execute arbitrar… | Patch early | 9.3 high | 40% | 2009-02-26 |
| CVE-2009-3033 EXP | Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Sy… | Patch early | 9.3 high | 40% | 2009-11-25 |
| CVE-1999-0368 EXP | Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. | Patch early | 10.0 high | 39.8% | 1999-02-09 |
| CVE-2012-0217 EXP | The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris… | Patch early | 7.2 high | 39.8% | 2012-06-12 |
| CVE-2010-1900 EXP | Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Vi… | Patch early | 9.3 high | 39.8% | 2010-08-11 |
| CVE-2004-0727 EXP | Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass… | Patch early | 7.5 high | 39.8% | 2004-07-27 |
| CVE-2007-1819 EXP | Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for Mercury Quality Center 9.0 befo… | Patch early | 9.3 high | 39.7% | 2007-04-02 |
| CVE-2012-2516 EXP | An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1,… | Patch early | 9.3 high | 39.7% | 2012-07-05 |
| CVE-2016-1104 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 39.6% | 2016-05-11 |
| CVE-2016-1096 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 39.6% | 2016-05-11 |
| CVE-2016-1102 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 39.6% | 2016-05-11 |
| CVE-2016-6816 EXP | The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP reques… | Patch early | 7.1 high | 39.6% | 2017-03-20 |
| CVE-2000-0834 EXP | The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challe… | Patch early | 7.5 high | 39.6% | 2000-11-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt