CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,157 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-24514 EXP | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to… | Patch early | 8.8 high | 30.5% | 2025-03-25 |
| CVE-2007-1347 EXP | Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial… | Patch early | 7.1 high | 30.3% | 2007-03-08 |
| CVE-2015-0065 EXP | Microsoft Word 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office docume… | Patch early | 9.3 high | 30.3% | 2015-02-11 |
| CVE-2015-2523 EXP | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Vie… | Patch early | 9.3 high | 30.3% | 2015-09-09 |
| CVE-2017-16524 EXP | Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authe… | Patch early | 8.8 high | 30.3% | 2017-11-06 |
| CVE-2018-19616 EXP | An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because acc… | Patch early | 8.1 high | 30.3% | 2018-12-26 |
| CVE-2014-1785 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 30.3% | 2014-06-11 |
| CVE-2010-0356 EXP | Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom Software Movie Player Pro SDK Ac… | Patch early | 9.3 high | 30.3% | 2010-01-18 |
| CVE-2015-2432 EXP | ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… | Patch early | 9.3 high | 30.3% | 2015-08-15 |
| CVE-2020-5844 EXP | index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts… | Patch early | 7.2 high | 30.3% | 2020-03-16 |
| CVE-2007-6331 EXP | Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe… | Patch early | 9.3 high | 30.1% | 2007-12-13 |
| CVE-2003-0665 EXP | Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 30.1% | 2003-10-20 |
| CVE-2003-0701 EXP | Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execut… | Patch early | 7.5 high | 30.1% | 2003-08-27 |
| CVE-2017-16995 EXP | The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption)… | Patch early | 7.8 high | 30.1% | 2017-12-27 |
| CVE-2015-0040 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 30% | 2015-02-11 |
| CVE-2019-15715 EXP | MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution. | Patch early | 7.2 high | 30% | 2019-10-09 |
| CVE-2015-8046 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux,… | Patch early | 10.0 high | 30% | 2015-11-11 |
| CVE-2015-0064 EXP | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applications 2010 SP2, Word Viewer, a… | Patch early | 9.3 high | 30% | 2015-02-11 |
| CVE-2015-1158 EXP | The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name… | Patch early | 10.0 high | 29.9% | 2015-06-26 |
| CVE-2017-2933 EXP | Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture compression. Successful exploita… | Patch early | 8.8 high | 29.9% | 2017-01-11 |
| CVE-2017-2935 EXP | Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file form… | Patch early | 8.8 high | 29.9% | 2017-01-11 |
| CVE-2017-2934 EXP | Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Texture Format files. Successful… | Patch early | 8.8 high | 29.9% | 2017-01-11 |
| CVE-2015-2431 EXP | Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote… | Patch early | 9.3 high | 29.8% | 2015-08-15 |
| CVE-2009-1558 EXP | Directory traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote… | Patch early | 7.8 high | 29.8% | 2009-05-06 |
| CVE-2018-12980 EXP | An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user… | Patch early | 8.8 high | 29.8% | 2018-07-12 |
| CVE-2012-0830 EXP | The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a lar… | Patch early | 7.5 high | 29.8% | 2012-02-06 |
| CVE-2018-12636 EXP | The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs pag… | Patch early | 7.2 high | 29.8% | 2018-06-22 |
| CVE-2008-0551 EXP | The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remo… | Patch early | 9.3 high | 29.7% | 2008-02-01 |
| CVE-2007-6401 EXP | Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote a… | Patch early | 9.3 high | 29.7% | 2007-12-17 |
| CVE-2019-9810 EXP | Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vu… | Patch early | 8.8 high | 29.7% | 2019-04-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt