CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,034 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-0168 EXP | The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Prote… | Patch early | 7.5 high | 19.9% | 2007-01-11 |
| CVE-2002-0540 EXP | Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CV… | Patch early | 7.5 high | 19.9% | 2002-07-03 |
| CVE-2017-16921 EXP | In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged i… | Patch early | 8.8 high | 19.9% | 2017-12-08 |
| CVE-2016-4273 EXP | Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to… | Patch early | 8.8 high | 19.9% | 2016-10-13 |
| CVE-2007-5466 EXP | Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the… | Patch early | 10.0 high | 19.9% | 2007-10-15 |
| CVE-2006-1982 EXP | Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remot… | Patch early | 7.5 high | 19.9% | 2006-04-21 |
| CVE-2015-5568 EXP | Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Ado… | Patch early | 10.0 high | 19.9% | 2015-09-22 |
| CVE-2007-0977 EXP | IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible thro… | Patch early | 7.1 high | 19.9% | 2007-02-16 |
| CVE-2012-2376 EXP | Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted a… | Patch early | 10.0 high | 19.8% | 2012-05-21 |
| CVE-2000-0061 EXP | Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, whic… | Patch early | 10.0 high | 19.8% | 2000-01-07 |
| CVE-2006-5972 EXP | Stack-based buffer overflow in WG111v2.SYS in NetGear WG111v2 wireless adapter (USB) allows remote attackers to execute arbitrary code via a long 802.… | Patch early | 10.0 high | 19.8% | 2006-11-18 |
| CVE-2010-1349 EXP | Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a hea… | Patch early | 10.0 high | 19.8% | 2010-04-12 |
| CVE-2019-18951 EXP | SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files. | Patch early | 7.5 high | 19.8% | 2019-11-13 |
| CVE-2011-1609 EXP | SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 b… | Patch early | 8.5 high | 19.8% | 2011-05-03 |
| CVE-2001-0909 EXP | Buffer overflow in helpctr.exe program in Microsoft Help Center for Windows XP allows remote attackers to execute arbitrary code via a long hcp: URL. | Patch early | 7.5 high | 19.7% | 2001-11-21 |
| CVE-2014-4492 EXP | libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data… | Patch early | 7.5 high | 19.7% | 2015-01-30 |
| CVE-2001-1088 EXP | Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled… | Patch early | 7.5 high | 19.7% | 2001-06-05 |
| CVE-2009-1869 EXP | Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Ad… | Patch early | 9.3 high | 19.7% | 2009-07-31 |
| CVE-2016-1002 EXP | Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21… | Patch early | 8.8 high | 19.7% | 2016-03-12 |
| CVE-2002-1426 EXP | HP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request containing 85 characters, poss… | Patch early | 7.8 high | 19.7% | 2003-04-11 |
| CVE-2007-4916 EXP | Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundatio… | Patch early | 10.0 high | 19.7% | 2007-09-17 |
| CVE-2016-0964 EXP | Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0… | Patch early | 8.8 high | 19.7% | 2016-02-10 |
| CVE-2016-0965 EXP | Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0… | Patch early | 8.8 high | 19.7% | 2016-02-10 |
| CVE-2016-0967 EXP | Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0… | Patch early | 8.8 high | 19.7% | 2016-02-10 |
| CVE-2010-4282 EXP | Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) t… | Patch early | 7.5 high | 19.6% | 2010-12-02 |
| CVE-2010-1296 EXP | Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) .ASL,… | Patch early | 9.3 high | 19.6% | 2010-05-27 |
| CVE-2009-2762 EXP | wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the adminis… | Patch early | 7.5 high | 19.6% | 2009-08-13 |
| CVE-2009-0949 EXP | The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote a… | Patch early | 7.5 high | 19.6% | 2009-06-09 |
| CVE-2011-0364 EXP | The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers to create arbitrary files and… | Patch early | 10.0 high | 19.6% | 2011-02-19 |
| CVE-2019-16701 EXP | pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metach… | Patch early | 8.8 high | 19.6% | 2019-09-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt