CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,331 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
400,331 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-4790 EXP | Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fp… | Patch early | 7.5 high | 54.9% | 2007-09-10 |
| CVE-2003-0347 EXP | Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to exe… | Patch early | 10.0 high | 54.9% | 2003-10-20 |
| CVE-2004-0594 EXP | The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allo… | Patch early | 5.1 medium | 54.9% | 2004-07-27 |
| CVE-2007-2485 EXP | PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute… | Patch early | 7.5 high | 54.9% | 2007-05-03 |
| CVE-2008-2168 EXP | Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded… | Patch early | 4.3 medium | 54.9% | 2008-05-13 |
| CVE-2017-11810 EXP | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows… | Patch early | 7.5 high | 54.8% | 2017-10-13 |
| CVE-2016-3357 EXP | Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word… | Patch early | 7.8 high | 54.8% | 2016-09-14 |
| CVE-2007-2222 EXP | Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explor… | Patch early | 9.3 high | 54.7% | 2007-06-12 |
| CVE-2014-5446 EXP | Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote a… | Patch early | 5.0 medium | 54.7% | 2014-12-04 |
| CVE-2007-2888 EXP | Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string… | Patch early | 7.6 high | 54.7% | 2007-05-30 |
| CVE-2012-0270 EXP | Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the get… | Patch early | 7.5 high | 54.7% | 2014-02-17 |
| CVE-2011-5124 EXP | Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 and ProxyOne, allows remote atta… | Patch early | 10.0 high | 54.6% | 2012-08-26 |
| CVE-2007-1765 EXP | Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (… | Patch early | 9.3 high | 54.6% | 2007-03-30 |
| CVE-2009-4223 EXP | PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL… | Patch early | 7.5 high | 54.6% | 2009-12-07 |
| CVE-2017-8657 EXP | Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the cu… | Patch early | 7.5 high | 54.6% | 2017-08-08 |
| CVE-2008-3008 EXP | Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers… | Patch early | 9.3 high | 54.6% | 2008-09-11 |
| CVE-2022-36267 EXP | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can… | Patch early | 9.8 critical | 54.5% | 2022-08-08 |
| CVE-2019-16667 EXP | diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs be… | Patch early | 8.8 high | 54.5% | 2019-09-26 |
| CVE-2010-3863 EXP | Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows r… | Patch early | 5.0 medium | 54.5% | 2010-11-05 |
| CVE-2009-1730 EXP | Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via… | Patch early | 10.0 high | 54.5% | 2009-05-20 |
| CVE-2016-2056 EXP | xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the a… | Patch early | 8.8 high | 54.5% | 2016-04-13 |
| CVE-2022-24562 EXP | In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the enti… | Patch early | 9.8 critical | 54.5% | 2022-06-16 |
| CVE-2024-11972 EXP | The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install an… | Patch early | 9.8 critical | 54.5% | 2024-12-31 |
| CVE-2012-0202 EXP | Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2 allow remote attackers to… | Patch early | 10.0 high | 54.5% | 2012-05-04 |
| CVE-2025-49132 EXP | Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespac… | Patch early | 10.0 critical | 54.5% | 2025-06-20 |
| CVE-2002-0371 EXP | Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to exec… | Patch early | 7.5 high | 54.4% | 2002-07-03 |
| CVE-2007-3040 EXP | Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a… | Patch early | 9.3 high | 54.4% | 2007-09-12 |
| CVE-2021-36356 EXP | KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary e… | Patch early | 9.8 critical | 54.4% | 2021-08-31 |
| CVE-2011-0027 EXP | Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation f… | Patch early | 9.3 high | 54.4% | 2011-01-12 |
| CVE-2023-41425 EXP | Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded… | Patch early | 6.1 medium | 54.3% | 2023-11-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt