CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,516 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-0232 EXP | includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metachar… | Patch early | 7.5 high | 47.9% | 2013-03-20 |
| CVE-2010-4701 EXP | Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows… | Patch early | 7.6 high | 47.8% | 2011-01-20 |
| CVE-2012-4361 EXP | lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via sh… | Patch early | 7.7 high | 47.8% | 2012-08-20 |
| CVE-2014-9566 EXP | Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as u… | Patch early | 7.5 high | 47.7% | 2015-03-10 |
| CVE-2012-3569 EXP | Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and oth… | Patch early | 9.3 high | 47.7% | 2012-11-14 |
| CVE-2004-0121 EXP | Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when c… | Patch early | 7.5 high | 47.7% | 2004-04-15 |
| CVE-2005-0063 EXP | The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers t… | Patch early | 7.5 high | 47.6% | 2005-05-02 |
| CVE-2018-1000811 EXP | bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Rem… | Patch early | 8.8 high | 47.6% | 2018-12-20 |
| CVE-2015-3089 EXP | Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17… | Patch early | 10.0 high | 47.6% | 2015-05-13 |
| CVE-2015-3093 EXP | Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17… | Patch early | 10.0 high | 47.6% | 2015-05-13 |
| CVE-2011-1248 EXP | WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remo… | Patch early | 9.3 high | 47.6% | 2011-05-13 |
| CVE-2018-8544 EXP | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code E… | Patch early | 8.8 high | 47.6% | 2018-11-14 |
| CVE-2021-27964 EXP | SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFil… | Patch early | 9.8 critical | 47.5% | 2021-03-05 |
| CVE-2009-2514 EXP | win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of… | Patch early | 9.3 high | 47.5% | 2009-11-11 |
| CVE-2021-40875 EXP | Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5… | Patch early | 7.5 high | 47.5% | 2021-09-22 |
| CVE-2006-4193 EXP | Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary co… | Patch early | 7.5 high | 47.5% | 2006-08-17 |
| CVE-2005-0688 EXP | Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP pac… | Patch early | 5.0 medium | 47.4% | 2005-03-05 |
| CVE-2017-11155 EXP | An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitiv… | Patch early | 7.5 high | 47.4% | 2017-08-08 |
| CVE-2014-2424 EXP | Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect… | Patch early | 4.0 medium | 47.4% | 2014-04-16 |
| CVE-2014-2299 EXP | Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote… | Patch early | 9.3 high | 47.4% | 2014-03-11 |
| CVE-2018-5767 EXP | An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with… | Patch early | 9.8 critical | 47.4% | 2018-02-15 |
| CVE-2006-5085 EXP | Static code injection vulnerability in config.php in Blog Pixel Motion 2.1.1 allows remote attackers to execute arbitrary PHP code via the nom_blog pa… | Patch early | 7.5 high | 47.3% | 2006-09-29 |
| CVE-2007-4983 EXP | Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote att… | Patch early | 10.0 high | 47.3% | 2007-09-19 |
| CVE-2016-3316 EXP | Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Offic… | Patch early | 7.8 high | 47.2% | 2016-08-09 |
| CVE-2018-15812 EXP | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy. | Patch early | 7.5 high | 47.2% | 2019-07-03 |
| CVE-2005-1815 EXP | Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute ar… | Patch early | 5.0 medium | 47.2% | 2005-06-01 |
| CVE-2014-2962 EXP | Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attack… | Patch early | 7.8 high | 47.1% | 2014-06-19 |
| CVE-2008-5405 EXP | Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier, allows remote attackers to ex… | Patch early | 9.3 high | 47% | 2008-12-10 |
| CVE-2004-0214 EXP | Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious ser… | Patch early | 10.0 high | 47% | 2004-11-03 |
| CVE-2014-9013 EXP | The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbi… | Patch early | 8.8 high | 46.9% | 2019-11-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt