CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,451 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-2336 EXP | sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings… | Patch early | 5.0 medium | 50.3% | 2012-05-11 |
| CVE-2014-7285 EXP | The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by… | Patch early | 6.5 medium | 50.3% | 2014-12-17 |
| CVE-2017-16720 EXP | A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the t… | Patch early | 9.8 critical | 50.3% | 2018-01-05 |
| CVE-2017-6465 EXP | Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; howeve… | Patch early | 9.8 critical | 50.3% | 2017-03-10 |
| CVE-2015-5127 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199… | Patch early | 10.0 high | 50.3% | 2015-08-14 |
| CVE-2015-5130 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199… | Patch early | 10.0 high | 50.3% | 2015-08-14 |
| CVE-2015-5134 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199… | Patch early | 10.0 high | 50.3% | 2015-08-14 |
| CVE-2022-36633 EXP | Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by U… | Patch early | 8.8 high | 50.3% | 2022-08-24 |
| CVE-2012-3363 EXP | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attac… | Patch early | 9.1 critical | 50.2% | 2013-02-13 |
| CVE-2010-0477 EXP | The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remot… | Patch early | 10.0 high | 50.2% | 2010-04-14 |
| CVE-2017-14535 EXP | trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php. | Patch early | 8.8 high | 50.1% | 2018-02-16 |
| CVE-2017-11890 EXP | Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703… | Patch early | 7.5 high | 50.1% | 2017-12-12 |
| CVE-2012-4915 EXP | Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .… | Patch early | 5.0 medium | 50% | 2014-05-29 |
| CVE-2017-8538 EXP | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… | Patch early | 7.8 high | 50% | 2017-05-26 |
| CVE-2007-2386 EXP | Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or… | Patch early | 9.4 high | 50% | 2007-05-24 |
| CVE-2003-0309 EXP | Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document wi… | Patch early | 7.5 high | 50% | 2003-06-09 |
| CVE-2007-2864 EXP | Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote a… | Patch early | 9.3 high | 49.9% | 2007-06-06 |
| CVE-2005-1219 EXP | Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC p… | Patch early | 7.5 high | 49.9% | 2005-07-12 |
| CVE-2025-58434 EXP | Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint… | Patch early | 9.8 critical | 49.9% | 2025-09-12 |
| CVE-2016-6909 EXP | Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 a… | Patch early | 9.8 critical | 49.9% | 2016-08-24 |
| CVE-2016-3313 EXP | Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary c… | Patch early | 7.8 high | 49.8% | 2016-08-09 |
| CVE-2002-1217 EXP | Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary co… | Patch early | 7.5 high | 49.8% | 2002-10-28 |
| CVE-2015-2994 EXP | Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by up… | Patch early | 6.5 medium | 49.8% | 2015-06-08 |
| CVE-2017-8682 EXP | Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows… | Patch early | 8.8 high | 49.8% | 2017-09-13 |
| CVE-2007-2447 EXP | The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters invol… | Patch early | 6.0 medium | 49.8% | 2007-05-14 |
| CVE-2026-23918 EXP | Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are… | Patch early | 8.8 high | 49.7% | 2026-05-04 |
| CVE-2011-3486 EXP | Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers… | Patch early | 5.0 medium | 49.7% | 2011-09-16 |
| CVE-2004-1135 EXP | Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2)… | Patch early | 5.0 medium | 49.6% | 2005-01-10 |
| CVE-2017-11793 EXP | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows… | Patch early | 7.5 high | 49.6% | 2017-10-13 |
| CVE-2006-0006 EXP | Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000… | Patch early | 9.3 high | 49.6% | 2006-02-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt