CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,987 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-3752 EXP | Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a denial of service (application c… | Patch early | 9.3 high | 36% | 2012-11-09 |
| CVE-2010-1527 EXP | Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter i… | Patch early | 9.3 high | 36% | 2010-08-23 |
| CVE-2008-5518 EXP | Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allo… | Patch early | 9.4 high | 35.9% | 2009-04-17 |
| CVE-2014-0784 EXP | Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a cr… | Patch early | 8.3 high | 35.9% | 2014-03-14 |
| CVE-2012-5975 EXP | The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 through 6.3.2… | Patch early | 9.3 high | 35.9% | 2012-12-04 |
| CVE-2007-5107 EXP | Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media ask.com Ask Toolbar 4.0.2.53… | Patch early | 9.3 high | 35.9% | 2007-09-26 |
| CVE-2018-16288 EXP | LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs. | Patch early | 8.6 high | 35.8% | 2018-09-14 |
| CVE-2005-0511 EXP | misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 35.8% | 2005-02-21 |
| CVE-2021-22146 EXP | All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting… | Patch early | 7.5 high | 35.8% | 2021-07-21 |
| CVE-2007-1658 EXP | Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) U… | Patch early | 9.3 high | 35.8% | 2007-03-24 |
| CVE-2015-3783 EXP | SceneKit in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and applicatio… | Patch early | 7.5 high | 35.8% | 2015-08-16 |
| CVE-2008-3571 EXP | The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900. | Patch early | 7.8 high | 35.7% | 2008-08-10 |
| CVE-2022-47878 EXP | Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the locat… | Patch early | 8.8 high | 35.7% | 2023-05-02 |
| CVE-2003-1336 EXP | Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL. | Patch early | 9.3 high | 35.7% | 2003-12-31 |
| CVE-2010-2746 EXP | Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist… | Patch early | 7.6 high | 35.7% | 2010-10-13 |
| CVE-2015-2510 EXP | Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 SP3, Office 2010 SP2, Lync 2010… | Patch early | 9.3 high | 35.6% | 2015-09-09 |
| CVE-2013-6420 EXP | The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1… | Patch early | 7.5 high | 35.6% | 2013-12-17 |
| CVE-2021-43405 EXP | An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric). | Patch early | 8.8 high | 35.6% | 2021-11-05 |
| CVE-2015-2464 EXP | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Go… | Patch early | 9.3 high | 35.6% | 2015-08-15 |
| CVE-2015-2462 EXP | ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… | Patch early | 9.3 high | 35.6% | 2015-08-15 |
| CVE-2015-2456 EXP | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Go… | Patch early | 9.3 high | 35.6% | 2015-08-15 |
| CVE-2018-13109 EXP | All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to… | Patch early | 7.5 high | 35.5% | 2018-07-06 |
| CVE-2008-2908 EXP | Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attacker… | Patch early | 9.3 high | 35.4% | 2008-06-30 |
| CVE-2007-3435 EXP | Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote a… | Patch early | 9.3 high | 35.4% | 2007-06-27 |
| CVE-2007-0325 EXP | Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7… | Patch early | 9.3 high | 35.4% | 2007-02-20 |
| CVE-2004-1104 EXP | Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page t… | Patch early | 7.5 high | 35.3% | 2004-12-31 |
| CVE-2015-6104 EXP | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Serv… | Patch early | 9.3 high | 35.3% | 2015-11-11 |
| CVE-2015-6103 EXP | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Serv… | Patch early | 9.3 high | 35.3% | 2015-11-11 |
| CVE-2008-5492 EXP | Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX Control allows remote attacke… | Patch early | 9.3 high | 35.3% | 2008-12-12 |
| CVE-2007-0348 EXP | Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.2… | Patch early | 9.3 high | 35.1% | 2007-03-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt