CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,486 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2003-0725 EXP | Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 an… | Patch early | 7.5 high | 48.6% | 2003-10-20 |
| CVE-2017-11855 EXP | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows… | Patch early | 7.5 high | 48.6% | 2017-11-15 |
| CVE-2018-14392 EXP | The New Threads plugin before 1.2 for MyBB has XSS. | Patch early | 6.1 medium | 48.6% | 2018-07-19 |
| CVE-2013-2568 EXP | A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a re… | Patch early | 9.8 critical | 48.5% | 2020-01-29 |
| CVE-1999-0209 EXP | The SunView (SunTools) selection_svc facility allows remote users to read files. | Patch early | 5.0 medium | 48.5% | 1990-08-14 |
| CVE-2005-1990 EXP | Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a… | Patch early | 5.1 medium | 48.5% | 2005-08-10 |
| CVE-2017-9232 EXP | Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege… | Patch early | 9.8 critical | 48.5% | 2017-05-28 |
| CVE-2019-0768 EXP | A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific con… | Patch early | 4.3 medium | 48.5% | 2019-04-09 |
| CVE-2002-0648 EXP | The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML fil… | Patch early | 5.0 medium | 48.4% | 2002-09-24 |
| CVE-2009-0182 EXP | Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as… | Patch early | 8.8 high | 48.4% | 2009-01-20 |
| CVE-2003-0816 EXP | Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL co… | Patch early | 7.5 high | 48.4% | 2004-02-03 |
| CVE-2011-2657 EXP | Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in N… | Patch early | 6.8 medium | 48.4% | 2012-07-26 |
| CVE-2020-5377 EXP | Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote atta… | Patch early | 9.1 critical | 48.3% | 2020-07-28 |
| CVE-2008-1059 EXP | PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers t… | Patch early | 7.5 high | 48.3% | 2008-02-28 |
| CVE-2010-0028 EXP | Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a c… | Patch early | 9.3 high | 48.3% | 2010-02-10 |
| CVE-2013-2827 EXP | An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers… | Patch early | 7.5 high | 48.3% | 2014-01-15 |
| CVE-2019-17503 EXP | An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGI… | Patch early | 5.3 medium | 48.3% | 2019-10-11 |
| CVE-2018-0706 EXP | Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access sensitive in… | Patch early | 8.8 high | 48.3% | 2018-07-17 |
| CVE-2008-0116 EXP | Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to… | Patch early | 9.3 high | 48.2% | 2008-03-11 |
| CVE-2013-2143 EXP | The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows re… | Patch early | 6.5 medium | 48.2% | 2014-04-17 |
| CVE-2006-3281 EXP | Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code v… | Patch early | 5.1 medium | 48.2% | 2006-06-28 |
| CVE-2013-5576 EXP | administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authentica… | Patch early | 6.8 medium | 48.2% | 2013-10-09 |
| CVE-2010-0270 EXP | The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote S… | Patch early | 10.0 high | 48.2% | 2010-04-14 |
| CVE-2018-8096 EXP | Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","V… | Patch early | 9.8 critical | 48.2% | 2018-03-14 |
| CVE-2001-0986 EXP | SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attribut… | Patch early | 5.0 medium | 48.2% | 2001-09-14 |
| CVE-2008-1547 EXP | Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows re… | Patch early | 4.3 medium | 48.1% | 2008-10-21 |
| CVE-2016-7189 EXP | The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Remote… | Patch early | 7.5 high | 48.1% | 2016-10-14 |
| CVE-2017-8541 EXP | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… | Patch early | 7.8 high | 48.1% | 2017-05-26 |
| CVE-2006-2766 EXP | Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other p… | Patch early | 2.6 low | 47.9% | 2006-06-02 |
| CVE-2012-2110 EXP | The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly inte… | Patch early | 7.5 high | 47.9% | 2012-04-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt