CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,534 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1375 EXP | The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response. | Patch early | 7.5 high | 23.5% | 2002-12-23 |
| CVE-2010-3139 EXP | Untrusted search path vulnerability in Microsoft Windows Progman Group Converter (grpconv.exe) allows local users, and possibly remote attackers, to e… | Patch early | 9.3 high | 23.5% | 2010-08-27 |
| CVE-2022-31101 EXP | prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated custo… | Patch early | 8.1 high | 23.5% | 2022-06-27 |
| CVE-2024-56902 EXP | Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information,… | Patch early | 7.5 high | 23.4% | 2025-02-03 |
| CVE-2013-1606 EXP | Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allows remote attackers to execute… | Patch early | 7.5 high | 23.4% | 2013-07-18 |
| CVE-2015-7622 EXP | Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acr… | Patch early | 10.0 high | 23.4% | 2015-10-14 |
| CVE-2008-3529 EXP | Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a d… | Patch early | 10.0 high | 23.4% | 2008-09-12 |
| CVE-2002-0647 EXP | Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote a… | Patch early | 7.5 high | 23.3% | 2002-09-24 |
| CVE-2004-2289 EXP | Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo sp… | Patch early | 10.0 high | 23.3% | 2004-12-31 |
| CVE-2012-2052 EXP | Stack-based buffer overflow in the U3D.8BI library plugin in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attac… | Patch early | 9.3 high | 23.3% | 2014-06-19 |
| CVE-2008-2281 EXP | Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers t… | Patch early | 9.3 high | 23.2% | 2008-05-18 |
| CVE-2014-8147 EXP | The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Un… | Patch early | 7.5 high | 23.2% | 2015-05-25 |
| CVE-2009-1960 EXP | inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute… | Patch early | 9.3 high | 23.2% | 2009-06-08 |
| CVE-2007-0021 EXP | Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash)… | Patch early | 7.5 high | 23.1% | 2007-01-23 |
| CVE-2019-11354 EXP | The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be… | Patch early | 7.8 high | 23.1% | 2019-04-19 |
| CVE-2011-1938 EXP | Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers… | Patch early | 7.5 high | 23.1% | 2011-05-31 |
| CVE-2002-2029 EXP | PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly exec… | Patch early | 7.5 high | 23.1% | 2002-12-31 |
| CVE-2002-0033 EXP | Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long dir… | Patch early | 10.0 high | 23.1% | 2002-05-29 |
| CVE-2014-4971 EXP | Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locat… | Patch early | 7.2 high | 23% | 2014-07-26 |
| CVE-2025-26264 EXP | GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Set… | Patch early | 8.8 high | 23% | 2025-02-27 |
| CVE-2014-2777 EXP | Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, ak… | Patch early | 7.5 high | 23% | 2014-06-11 |
| CVE-2013-2470 EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0… | Patch early | 10.0 high | 23% | 2013-06-18 |
| CVE-2013-2472 EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0… | Patch early | 10.0 high | 23% | 2013-06-18 |
| CVE-2007-5863 EXP | Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the clien… | Patch early | 9.3 high | 23% | 2007-12-19 |
| CVE-2007-5133 EXP | Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file… | Patch early | 7.1 high | 22.9% | 2007-09-27 |
| CVE-2010-3131 EXP | Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaM… | Patch early | 9.3 high | 22.9% | 2010-08-26 |
| CVE-2017-0781 EXP | A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.… | Patch early | 8.8 high | 22.9% | 2017-09-14 |
| CVE-2014-1775 EXP | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 22.8% | 2014-06-11 |
| CVE-2014-1803 EXP | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 22.8% | 2014-06-11 |
| CVE-2014-2757 EXP | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 22.8% | 2014-06-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt