CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,458 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
319,290 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-1766 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 33.3% | 2014-04-27 |
| CVE-2009-1394 EXP | Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed st… | Patch early | 9.3 high | 33.3% | 2009-06-26 |
| CVE-2009-1612 EXP | Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary… | Patch early | 9.3 high | 33.3% | 2009-05-11 |
| CVE-2025-1097 EXP | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be… | Patch early | 8.8 high | 33.2% | 2025-03-25 |
| CVE-2019-15813 EXP | Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell. | Patch early | 8.8 high | 33.2% | 2019-09-04 |
| CVE-2020-29607 EXP | A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "mana… | Patch early | 7.2 high | 33.2% | 2020-12-16 |
| CVE-2010-4321 EXP | Stack-based buffer overflow in an ActiveX control in ienipp.ocx in Novell iPrint Client 5.52 allows remote attackers to execute arbitrary code via a l… | Patch early | 9.3 high | 33.2% | 2010-12-30 |
| CVE-2015-3337 EXP | Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read… | Patch early | 4.3 medium | 33.2% | 2015-05-01 |
| CVE-2016-4226 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… | Patch early | 8.8 high | 33.1% | 2016-07-13 |
| CVE-2016-4228 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… | Patch early | 8.8 high | 33.1% | 2016-07-13 |
| CVE-2021-45043 EXP | HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter. | Patch early | 7.5 high | 33.1% | 2021-12-15 |
| CVE-2012-2288 EXP | Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers t… | Patch early | 9.3 high | 33.1% | 2012-09-04 |
| CVE-2015-1376 EXP | pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write… | Patch early | 4.0 medium | 33.1% | 2015-01-28 |
| CVE-2018-14716 EXP | A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elemen… | Patch early | 7.5 high | 33% | 2018-08-06 |
| CVE-2007-4515 EXP | Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 all… | Patch early | 9.3 high | 33% | 2007-08-31 |
| CVE-2009-1028 EXP | Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file. | Patch early | 9.3 high | 33% | 2009-03-20 |
| CVE-2011-1213 EXP | Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via… | Patch early | 9.3 high | 33% | 2011-05-31 |
| CVE-2007-3068 EXP | Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long fi… | Patch early | 6.8 medium | 32.9% | 2007-06-06 |
| CVE-2016-4227 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… | Patch early | 8.8 high | 32.9% | 2016-07-13 |
| CVE-2016-4231 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… | Patch early | 8.8 high | 32.9% | 2016-07-13 |
| CVE-2012-1007 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the… | Patch early | 4.3 medium | 32.9% | 2012-02-07 |
| CVE-2018-19458 EXP | In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability t… | Patch early | 7.5 high | 32.9% | 2018-11-22 |
| CVE-2014-1799 EXP | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 32.9% | 2014-06-11 |
| CVE-2005-1979 EXP | Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "… | Patch early | 5.0 medium | 32.8% | 2005-10-12 |
| CVE-2010-4588 EXP | The WBEMSingleView.ocx ActiveX control 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier allows remote attackers to execute arbitrary… | Patch early | 9.3 high | 32.8% | 2010-12-23 |
| CVE-2008-3364 EXP | Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-De… | Patch early | 9.3 high | 32.8% | 2008-07-30 |
| CVE-2015-3137 EXP | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… | Patch early | 10.0 high | 32.8% | 2015-07-09 |
| CVE-2015-4430 EXP | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… | Patch early | 10.0 high | 32.8% | 2015-07-09 |
| CVE-2008-0871 EXP | Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long pa… | Patch early | 6.8 medium | 32.8% | 2008-02-21 |
| CVE-2004-2434 EXP | Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace… | Patch early | 5.0 medium | 32.8% | 2004-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt