CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,003 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-9205 EXP | Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. | Patch early | 7.5 high | 55.1% | 2018-04-04 |
| CVE-2016-6602 EXP | ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartex… | Patch early | 9.8 critical | 55.1% | 2017-01-23 |
| CVE-2015-1833 EXP | XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2… | Patch early | 6.4 medium | 55% | 2015-05-29 |
| CVE-2006-4948 EXP | Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cau… | Patch early | 7.5 high | 55% | 2006-09-23 |
| CVE-2013-5877 EXP | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 1… | Patch early | 5.0 medium | 55% | 2014-01-15 |
| CVE-2018-10956 EXP | IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal. | Patch early | 7.5 high | 55% | 2018-06-25 |
| CVE-2019-11229 EXP | models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution. | Patch early | 8.8 high | 55% | 2019-04-15 |
| CVE-2018-0834 EXP | Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how t… | Patch early | 7.5 high | 54.9% | 2018-02-15 |
| CVE-2004-0389 EXP | RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a… | Patch early | 7.5 high | 54.9% | 2004-06-01 |
| CVE-2007-4790 EXP | Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fp… | Patch early | 7.5 high | 54.9% | 2007-09-10 |
| CVE-2003-0347 EXP | Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to exe… | Patch early | 10.0 high | 54.9% | 2003-10-20 |
| CVE-2004-0594 EXP | The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allo… | Patch early | 5.1 medium | 54.9% | 2004-07-27 |
| CVE-2007-2485 EXP | PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute… | Patch early | 7.5 high | 54.9% | 2007-05-03 |
| CVE-2008-2168 EXP | Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded… | Patch early | 4.3 medium | 54.9% | 2008-05-13 |
| CVE-2017-11810 EXP | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows… | Patch early | 7.5 high | 54.8% | 2017-10-13 |
| CVE-2016-3357 EXP | Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word… | Patch early | 7.8 high | 54.8% | 2016-09-14 |
| CVE-2007-2222 EXP | Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explor… | Patch early | 9.3 high | 54.7% | 2007-06-12 |
| CVE-2014-5446 EXP | Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote a… | Patch early | 5.0 medium | 54.7% | 2014-12-04 |
| CVE-2007-2888 EXP | Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string… | Patch early | 7.6 high | 54.7% | 2007-05-30 |
| CVE-2012-0270 EXP | Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the get… | Patch early | 7.5 high | 54.7% | 2014-02-17 |
| CVE-2011-5124 EXP | Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 and ProxyOne, allows remote atta… | Patch early | 10.0 high | 54.6% | 2012-08-26 |
| CVE-2007-1765 EXP | Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (… | Patch early | 9.3 high | 54.6% | 2007-03-30 |
| CVE-2009-4223 EXP | PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 54.6% | 2009-12-07 |
| CVE-2017-8657 EXP | Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the cu… | Patch early | 7.5 high | 54.6% | 2017-08-08 |
| CVE-2008-3008 EXP | Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers… | Patch early | 9.3 high | 54.6% | 2008-09-11 |
| CVE-2022-36267 EXP | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can… | Patch early | 9.8 critical | 54.5% | 2022-08-08 |
| CVE-2019-16667 EXP | diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs be… | Patch early | 8.8 high | 54.5% | 2019-09-26 |
| CVE-2010-3863 EXP | Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows r… | Patch early | 5.0 medium | 54.5% | 2010-11-05 |
| CVE-2009-1730 EXP | Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via… | Patch early | 10.0 high | 54.5% | 2009-05-20 |
| CVE-2016-2056 EXP | xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the a… | Patch early | 8.8 high | 54.5% | 2016-04-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt