CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,661 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-7982 EXP | Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the syste… | Patch early | 7.5 high | 20.5% | 2017-01-18 |
| CVE-2004-0399 EXP | Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denia… | Patch early | 7.5 high | 20.5% | 2004-07-07 |
| CVE-2010-3967 EXP | Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via a Trojan horse DLL in the cur… | Patch early | 9.3 high | 20.5% | 2010-12-16 |
| CVE-2017-13156 EXP | An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID… | Patch early | 7.8 high | 20.5% | 2017-12-06 |
| CVE-2016-4175 EXP | Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… | Patch early | 8.8 high | 20.5% | 2016-07-13 |
| CVE-2016-4179 EXP | Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… | Patch early | 8.8 high | 20.5% | 2016-07-13 |
| CVE-2013-1598 EXP | A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, whi… | Patch early | 8.8 high | 20.5% | 2020-01-24 |
| CVE-2014-1769 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-1774 EXP | Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web sit… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-1788 EXP | Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web sit… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-1802 EXP | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-1804 EXP | Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web sit… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2753 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2755 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2756 EXP | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2758 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2759 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2760 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2761 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2763 EXP | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2764 EXP | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2765 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2766 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2767 EXP | Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted w… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2768 EXP | Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2769 EXP | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2770 EXP | Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web sit… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2771 EXP | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2772 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2773 EXP | Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt