CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,935 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-0695 EXP | Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long FTP comma… | Patch early | 7.5 high | 38.2% | 2004-07-27 |
| CVE-2018-8474 EXP | A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Se… | Patch early | 7.5 high | 38.2% | 2018-09-13 |
| CVE-2015-5548 EXP | Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… | Patch early | 10.0 high | 38.2% | 2015-08-14 |
| CVE-2015-5545 EXP | Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… | Patch early | 10.0 high | 38.2% | 2015-08-14 |
| CVE-2015-5544 EXP | Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… | Patch early | 10.0 high | 38.2% | 2015-08-14 |
| CVE-2015-5549 EXP | Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… | Patch early | 10.0 high | 38.2% | 2015-08-14 |
| CVE-2015-5547 EXP | Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… | Patch early | 10.0 high | 38.2% | 2015-08-14 |
| CVE-2015-5546 EXP | Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.19… | Patch early | 10.0 high | 38.2% | 2015-08-14 |
| CVE-2007-0216 EXP | wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbi… | Patch early | 9.3 high | 38.1% | 2008-02-12 |
| CVE-2019-15977 EXP | Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker… | Patch early | 7.5 high | 38.1% | 2020-01-06 |
| CVE-2018-7583 EXP | Proxy.exe in DualDesk 20 allows Remote Denial Of Service (daemon crash) via a long string to TCP port 5500. | Patch early | 7.5 high | 38.1% | 2018-03-04 |
| CVE-2016-6896 EXP | Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authent… | Patch early | 7.1 high | 38.1% | 2017-01-18 |
| CVE-1999-0911 EXP | Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested… | Patch early | 10.0 high | 38.1% | 1999-08-27 |
| CVE-2007-6387 EXP | Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks,… | Patch early | 9.3 high | 38% | 2007-12-15 |
| CVE-2007-5603 EXP | Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remot… | Patch early | 9.3 high | 38% | 2007-11-05 |
| CVE-2015-2843 EXP | Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute arbitrary SQL commands via the… | Patch early | 7.5 high | 37.9% | 2015-05-12 |
| CVE-2009-4769 EXP | Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitr… | Patch early | 9.3 high | 37.9% | 2010-04-20 |
| CVE-2019-16893 EXP | The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a reboot.cgi reque… | Patch early | 7.5 high | 37.8% | 2020-02-03 |
| CVE-2010-0688 EXP | Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a crafted (1) .orb or (2) .ov f… | Patch early | 9.3 high | 37.8% | 2010-03-19 |
| CVE-2008-0660 EXP | Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploa… | Patch early | 9.3 high | 37.8% | 2008-02-08 |
| CVE-2008-4388 EXP | The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate down… | Patch early | 9.3 high | 37.7% | 2009-01-20 |
| CVE-2016-4108 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.7% | 2016-05-11 |
| CVE-2016-1101 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.7% | 2016-05-11 |
| CVE-2016-1105 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.7% | 2016-05-11 |
| CVE-2016-1103 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.7% | 2016-05-11 |
| CVE-2008-6221 EXP | PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remote attacke… | Patch early | 7.5 high | 37.7% | 2009-02-20 |
| CVE-2008-4385 EXP | Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the download and execution of arbitrary… | Patch early | 9.3 high | 37.7% | 2008-10-14 |
| CVE-2015-1328 EXP | The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions f… | Patch early | 7.8 high | 37.7% | 2016-11-28 |
| CVE-2003-0838 EXP | Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and insertin… | Patch early | 7.5 high | 37.6% | 2003-11-17 |
| CVE-2006-4924 EXP | sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH p… | Patch early | 7.8 high | 37.5% | 2006-09-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt