CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,034 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-4769 EXP | Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitr… | Patch early | 9.3 high | 37.9% | 2010-04-20 |
| CVE-2019-16893 EXP | The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a reboot.cgi reque… | Patch early | 7.5 high | 37.8% | 2020-02-03 |
| CVE-2010-0688 EXP | Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a crafted (1) .orb or (2) .ov f… | Patch early | 9.3 high | 37.8% | 2010-03-19 |
| CVE-2002-0325 EXP | Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL. | Patch early | 5.0 medium | 37.8% | 2002-06-25 |
| CVE-2008-0660 EXP | Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploa… | Patch early | 9.3 high | 37.8% | 2008-02-08 |
| CVE-2007-1683 EXP | Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to… | Patch early | 6.8 medium | 37.7% | 2007-04-26 |
| CVE-2002-1561 EXP | The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a ma… | Patch early | 5.0 medium | 37.7% | 2003-04-02 |
| CVE-2008-4388 EXP | The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate down… | Patch early | 9.3 high | 37.7% | 2009-01-20 |
| CVE-2008-1405 EXP | PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 6.8 medium | 37.7% | 2008-03-20 |
| CVE-2008-1416 EXP | Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the includ… | Patch early | 6.8 medium | 37.7% | 2008-03-20 |
| CVE-2016-1101 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.7% | 2016-05-11 |
| CVE-2016-1103 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.7% | 2016-05-11 |
| CVE-2016-1105 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.7% | 2016-05-11 |
| CVE-2016-4108 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.7% | 2016-05-11 |
| CVE-2008-4385 EXP | Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the download and execution of arbitrary… | Patch early | 9.3 high | 37.7% | 2008-10-14 |
| CVE-2015-1328 EXP | The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions f… | Patch early | 7.8 high | 37.7% | 2016-11-28 |
| CVE-2008-6829 EXP | VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (forward slash, backward slash, f… | Patch early | 5.0 medium | 37.6% | 2009-06-08 |
| CVE-2007-5457 EXP | Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (com_jfu or com_joomla_flash_uploader) 2.5.1 component for… | Patch early | 6.8 medium | 37.6% | 2007-10-14 |
| CVE-2003-0838 EXP | Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and insertin… | Patch early | 7.5 high | 37.6% | 2003-11-17 |
| CVE-2006-4924 EXP | sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH p… | Patch early | 7.8 high | 37.5% | 2006-09-27 |
| CVE-2007-5412 EXP | Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joomla! allow remote attackers to… | Patch early | 6.8 medium | 37.5% | 2007-10-12 |
| CVE-2007-5843 EXP | PHP remote file inclusion vulnerability in includes/common.php in scWiki 1.0 Beta 2 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 6.8 medium | 37.5% | 2007-11-06 |
| CVE-2020-14008 EXP | Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which le… | Patch early | 7.2 high | 37.5% | 2020-09-04 |
| CVE-2009-1569 EXP | Multiple stack-based buffer overflows in Novell iPrint Client 4.38, 5.30, and possibly other versions before 5.32 allow remote attackers to execute ar… | Patch early | 9.3 high | 37.5% | 2009-12-08 |
| CVE-2011-1892 EXP | Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office Shar… | Patch early | 4.0 medium | 37.5% | 2011-09-15 |
| CVE-2007-5244 EXP | Stack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versions on Solaris, allows remote a… | Patch early | 9.3 high | 37.5% | 2007-10-06 |
| CVE-2007-3382 EXP | Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies… | Patch early | 4.3 medium | 37.5% | 2007-08-14 |
| CVE-2019-15978 EXP | Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker… | Patch early | 7.2 high | 37.5% | 2020-01-06 |
| CVE-2012-0198 EXP | Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Softwa… | Patch early | 9.3 high | 37.4% | 2012-03-06 |
| CVE-2009-1547 EXP | Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted dat… | Patch early | 8.8 high | 37.4% | 2009-10-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt