CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,405 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
149,558 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-1247 EXP | Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD… | Patch early | 9.3 high | 22.4% | 2010-06-08 |
| CVE-2003-0681 EXP | A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-spec… | Patch early | 7.5 high | 22.4% | 2003-10-06 |
| CVE-2010-1245 EXP | Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac all… | Patch early | 9.3 high | 22.4% | 2010-06-08 |
| CVE-2004-0835 EXP | MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead o… | Patch early | 7.5 high | 22.4% | 2004-11-03 |
| CVE-2017-3106 EXP | Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation co… | Patch early | 8.8 high | 22.3% | 2017-08-11 |
| CVE-2014-2782 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 22.3% | 2014-06-19 |
| CVE-2013-0662 EXP | Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute a… | Patch early | 9.3 high | 22.3% | 2014-04-01 |
| CVE-2010-1717 EXP | Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitrary files and… | Patch early | 7.5 high | 22.3% | 2010-05-04 |
| CVE-2008-2469 EXP | Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitr… | Patch early | 10.0 high | 22.3% | 2008-10-23 |
| CVE-2006-7066 EXP | Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, d… | Patch early | 7.1 high | 22.2% | 2007-03-02 |
| CVE-2011-2131 EXP | Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a den… | Patch early | 9.3 high | 22.2% | 2011-08-11 |
| CVE-2008-0590 EXP | Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute… | Patch early | 9.0 high | 22.2% | 2008-02-05 |
| CVE-2006-2444 EXP | The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) vi… | Patch early | 7.8 high | 22.1% | 2006-05-25 |
| CVE-2006-4494 EXP | Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiat… | Patch early | 7.5 high | 22.1% | 2006-08-31 |
| CVE-2006-7206 EXP | Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and… | Patch early | 7.8 high | 22.1% | 2007-06-22 |
| CVE-2002-1179 EXP | Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digi… | Patch early | 7.5 high | 22.1% | 2002-10-28 |
| CVE-2022-4510 EXP | A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesyste… | Patch early | 7.8 high | 22% | 2023-01-26 |
| CVE-2013-3846 EXP | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (m… | Patch early | 9.3 high | 22% | 2013-12-29 |
| CVE-2018-19246 EXP | PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their… | Patch early | 7.5 high | 22% | 2018-11-13 |
| CVE-2003-0666 EXP | Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters… | Patch early | 7.5 high | 21.9% | 2003-10-20 |
| CVE-2020-10884 EXP | This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750… | Patch early | 8.8 high | 21.9% | 2020-03-25 |
| CVE-2010-1938 EXP | Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE… | Patch early | 9.3 high | 21.9% | 2010-05-28 |
| CVE-2007-3927 EXP | Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in… | Patch early | 10.0 high | 21.9% | 2007-07-21 |
| CVE-2012-0016 EXP | Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, and 4 allows local users to gai… | Patch early | 9.3 high | 21.9% | 2012-03-13 |
| CVE-2015-3302 EXP | The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers… | Patch early | 7.5 high | 21.8% | 2017-12-29 |
| CVE-2017-2985 EXP | Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class. Successful… | Patch early | 8.8 high | 21.8% | 2017-02-15 |
| CVE-2022-34047 EXP | An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/s… | Patch early | 7.5 high | 21.8% | 2022-07-20 |
| CVE-2014-1772 EXP | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | Patch early | 9.3 high | 21.7% | 2014-06-11 |
| CVE-2014-1805 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 21.7% | 2014-06-11 |
| CVE-2014-2754 EXP | Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web sit… | Patch early | 9.3 high | 21.7% | 2014-06-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt