CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,049 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-5963 EXP | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… | Patch early | 10.0 high | 36.9% | 2013-01-31 |
| CVE-2012-5964 EXP | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… | Patch early | 10.0 high | 36.9% | 2013-01-31 |
| CVE-2012-5965 EXP | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… | Patch early | 10.0 high | 36.9% | 2013-01-31 |
| CVE-2008-1074 EXP | PHP remote file inclusion vulnerability in lib/head_auth.php in GROUP-E 1.6.41 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 6.8 medium | 36.9% | 2008-02-29 |
| CVE-2007-3624 EXP | Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in the… | Patch early | 10.0 high | 36.8% | 2007-07-09 |
| CVE-2007-6530 EXP | Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury… | Patch early | 9.3 high | 36.8% | 2007-12-27 |
| CVE-2012-0201 EXP | Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote at… | Patch early | 9.3 high | 36.8% | 2012-03-02 |
| CVE-2008-1436 EXP | Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalServ… | Patch early | 9.0 high | 36.8% | 2008-04-21 |
| CVE-2011-3659 EXP | Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before… | Patch early | 9.3 high | 36.8% | 2012-02-01 |
| CVE-2018-6008 EXP | Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter. | Patch early | 7.5 high | 36.8% | 2018-01-29 |
| CVE-2015-3042 EXP | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to… | Patch early | 10.0 high | 36.8% | 2015-04-14 |
| CVE-2019-2588 EXP | Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported vers… | Patch early | 4.9 medium | 36.8% | 2019-04-23 |
| CVE-2017-13872 EXP | An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the "Directory Ut… | Patch early | 8.1 high | 36.8% | 2017-11-29 |
| CVE-2016-0120 EXP | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gol… | Patch early | 6.5 medium | 36.7% | 2016-03-09 |
| CVE-2009-0119 EXP | Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly… | Patch early | 10.0 high | 36.7% | 2009-01-14 |
| CVE-2010-2343 EXP | Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbitrary code via a crafted pls p… | Patch early | 9.3 high | 36.7% | 2010-06-21 |
| CVE-2009-3853 EXP | Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 be… | Patch early | 9.3 high | 36.7% | 2009-11-04 |
| CVE-2003-0111 EXP | The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote… | Patch early | 7.5 high | 36.7% | 2003-05-05 |
| CVE-2019-6814 EXP | A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to conf… | Patch early | 9.8 critical | 36.7% | 2019-05-22 |
| CVE-2017-16887 EXP | The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized… | Patch early | 9.8 critical | 36.6% | 2018-01-12 |
| CVE-2007-5660 EXP | Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2… | Patch early | 9.3 high | 36.6% | 2007-11-02 |
| CVE-2016-6435 EXP | The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug I… | Patch early | 6.5 medium | 36.6% | 2016-10-06 |
| CVE-2007-0352 EXP | Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt fi… | Patch early | 9.3 high | 36.6% | 2007-01-19 |
| CVE-2008-6504 EXP | ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly… | Patch early | 5.0 medium | 36.6% | 2009-03-23 |
| CVE-2007-2193 EXP | Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build 195 allows user-assisted remo… | Patch early | 9.3 high | 36.6% | 2007-04-24 |
| CVE-2007-3490 EXP | Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to t… | Patch early | 7.5 high | 36.6% | 2007-06-29 |
| CVE-2011-5130 EXP | dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers to execute arbitrary commands v… | Patch early | 6.8 medium | 36.6% | 2012-08-30 |
| CVE-2007-5800 EXP | Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute ar… | Patch early | 6.8 medium | 36.5% | 2007-11-03 |
| CVE-2007-5362 EXP | Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! all… | Patch early | 6.8 medium | 36.5% | 2007-10-11 |
| CVE-2017-0084 EXP | Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… | Patch early | 8.8 high | 36.5% | 2017-03-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt