CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,810 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-0252 EXP | internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted… | Patch early | 5.0 medium | 39.7% | 2015-03-24 |
| CVE-2007-5461 EXP | Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certai… | Patch early | 3.5 low | 39.7% | 2007-10-15 |
| CVE-2021-25156 EXP | A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x:… | Patch early | 4.9 medium | 39.7% | 2021-03-30 |
| CVE-2016-1096 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 39.6% | 2016-05-11 |
| CVE-2016-1102 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 39.6% | 2016-05-11 |
| CVE-2016-1104 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 39.6% | 2016-05-11 |
| CVE-2017-17968 EXP | A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbi… | Patch early | 9.8 critical | 39.6% | 2017-12-29 |
| CVE-2016-6816 EXP | The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP reques… | Patch early | 7.1 high | 39.6% | 2017-03-20 |
| CVE-2023-2068 EXP | The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using t… | Patch early | 9.8 critical | 39.6% | 2023-06-27 |
| CVE-2000-0834 EXP | The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challe… | Patch early | 7.5 high | 39.6% | 2000-11-14 |
| CVE-2019-17240 EXP | bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-… | Patch early | 9.8 critical | 39.6% | 2019-10-06 |
| CVE-2006-0030 EXP | Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to… | Patch early | 5.1 medium | 39.6% | 2006-03-14 |
| CVE-2014-1806 EXP | The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access,… | Patch early | 10.0 high | 39.6% | 2014-05-14 |
| CVE-2012-6066 EXP | freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client wi… | Patch early | 9.3 high | 39.5% | 2012-12-04 |
| CVE-2011-3478 EXP | The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12… | Patch early | 10.0 high | 39.5% | 2012-01-25 |
| CVE-2002-1412 EXP | Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable… | Patch early | 7.5 high | 39.5% | 2003-04-11 |
| CVE-2015-2067 EXP | Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attacker… | Patch early | 5.0 medium | 39.4% | 2015-02-24 |
| CVE-2007-4815 EXP | Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers to execute arbitrary PHP code… | Patch early | 6.8 medium | 39.4% | 2007-09-11 |
| CVE-2007-5631 EXP | Multiple PHP remote file inclusion vulnerabilities in PeopleAggregator 1.2pre6, when register_globals is enabled, allow remote attackers to execute ar… | Patch early | 6.8 medium | 39.4% | 2007-10-23 |
| CVE-2016-0111 EXP | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corr… | Patch early | 7.5 high | 39.4% | 2016-03-09 |
| CVE-2003-0113 EXP | Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response… | Patch early | 7.5 high | 39.4% | 2003-05-12 |
| CVE-2011-2757 EXP | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 39.4% | 2011-07-17 |
| CVE-2008-0115 EXP | Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remo… | Patch early | 9.3 high | 39.3% | 2008-03-11 |
| CVE-2013-4800 EXP | Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1735. | Patch early | 9.3 high | 39.3% | 2013-07-29 |
| CVE-2018-16133 EXP | Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI. | Patch early | 5.3 medium | 39.3% | 2018-08-29 |
| CVE-2017-14537 EXP | trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.p… | Patch early | 6.5 medium | 39.3% | 2018-02-16 |
| CVE-2018-10822 EXP | Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2… | Patch early | 7.5 high | 39.3% | 2018-10-17 |
| CVE-2015-3128 EXP | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… | Patch early | 10.0 high | 39.2% | 2015-07-09 |
| CVE-2014-2383 EXP | dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitra… | Patch early | 6.8 medium | 39.2% | 2014-04-28 |
| CVE-2017-12943 EXP | D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path trav… | Patch early | 9.8 critical | 39.2% | 2017-08-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt