CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,331 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
319,183 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-6435 EXP | The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug I… | Patch early | 6.5 medium | 36.6% | 2016-10-06 |
| CVE-2007-0352 EXP | Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt fi… | Patch early | 9.3 high | 36.6% | 2007-01-19 |
| CVE-2008-6504 EXP | ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly… | Patch early | 5.0 medium | 36.6% | 2009-03-23 |
| CVE-2007-2193 EXP | Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build 195 allows user-assisted remo… | Patch early | 9.3 high | 36.6% | 2007-04-24 |
| CVE-2007-3490 EXP | Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to t… | Patch early | 7.5 high | 36.6% | 2007-06-29 |
| CVE-2011-5130 EXP | dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers to execute arbitrary commands v… | Patch early | 6.8 medium | 36.6% | 2012-08-30 |
| CVE-2007-5800 EXP | Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute ar… | Patch early | 6.8 medium | 36.5% | 2007-11-03 |
| CVE-2007-5362 EXP | Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! all… | Patch early | 6.8 medium | 36.5% | 2007-10-11 |
| CVE-2017-0084 EXP | Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… | Patch early | 8.8 high | 36.5% | 2017-03-17 |
| CVE-2009-0546 EXP | Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbitrary code via a long text att… | Patch early | 9.3 high | 36.5% | 2009-02-12 |
| CVE-2019-17671 EXP | In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. | Patch early | 5.3 medium | 36.5% | 2019-10-17 |
| CVE-2007-0018 EXP | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers… | Patch early | 9.3 high | 36.5% | 2007-01-24 |
| CVE-2016-4232 EXP | Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… | Patch early | 7.5 high | 36.5% | 2016-07-13 |
| CVE-2018-7582 EXP | WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991. | Patch early | 7.5 high | 36.4% | 2018-03-09 |
| CVE-2011-3490 EXP | Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (cr… | Patch early | 10.0 high | 36.4% | 2011-09-16 |
| CVE-2008-5790 EXP | Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to ex… | Patch early | 7.5 high | 36.4% | 2008-12-31 |
| CVE-2014-8499 EXP | Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition bef… | Patch early | 6.5 medium | 36.4% | 2014-11-17 |
| CVE-2015-2461 EXP | ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… | Patch early | 9.3 high | 36.4% | 2015-08-15 |
| CVE-2012-4924 EXP | Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execut… | Patch early | 9.3 high | 36.3% | 2012-09-15 |
| CVE-2009-1831 EXP | The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted… | Patch early | 9.3 high | 36.3% | 2009-05-29 |
| CVE-2012-0393 EXP | The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to cr… | Patch early | 6.4 medium | 36.3% | 2012-01-08 |
| CVE-2012-0284 EXP | Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireles… | Patch early | 9.3 high | 36.3% | 2012-07-19 |
| CVE-2009-0215 EXP | Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo comp… | Patch early | 9.3 high | 36.3% | 2009-03-25 |
| CVE-2014-6036 EXP | Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3… | Patch early | 6.4 medium | 36.3% | 2014-12-04 |
| CVE-2022-26965 EXP | In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution. | Patch early | 7.2 high | 36.3% | 2022-03-18 |
| CVE-2008-3878 EXP | Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows r… | Patch early | 9.3 high | 36.2% | 2008-09-02 |
| CVE-2008-5664 EXP | Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows remote attackers to execute a… | Patch early | 9.3 high | 36.2% | 2008-12-19 |
| CVE-2007-2581 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server… | Patch early | 4.3 medium | 36.2% | 2007-05-09 |
| CVE-2007-2884 EXP | Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption)… | Patch early | 9.3 high | 36.2% | 2007-05-30 |
| CVE-2002-0659 EXP | The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encoding… | Patch early | 5.0 medium | 36.2% | 2002-08-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt