CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,045 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
149,730 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-1122 EXP | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… | Patch early | 8.8 high | 16.9% | 2019-07-15 |
| CVE-2019-1123 EXP | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… | Patch early | 8.8 high | 16.9% | 2019-07-15 |
| CVE-2019-1128 EXP | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… | Patch early | 8.8 high | 16.9% | 2019-07-15 |
| CVE-2010-1531 EXP | Directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a .. (d… | Patch early | 7.5 high | 16.9% | 2010-04-26 |
| CVE-2008-0250 EXP | Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with… | Patch early | 9.3 high | 16.9% | 2008-01-12 |
| CVE-2013-2678 EXP | Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive informati… | Patch early | 8.1 high | 16.9% | 2020-02-04 |
| CVE-2012-3282 EXP | Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code v… | Patch early | 10.0 high | 16.9% | 2013-02-06 |
| CVE-2008-5177 EXP | Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (1) execute arbitrary code on a Linux platfo… | Patch early | 10.0 high | 16.9% | 2008-11-20 |
| CVE-2008-3362 EXP | Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to exec… | Patch early | 10.0 high | 16.8% | 2008-07-30 |
| CVE-2010-3152 EXP | Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions allows local users, and possi… | Patch early | 9.3 high | 16.8% | 2010-08-27 |
| CVE-2007-1770 EXP | Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three t… | Patch early | 10.0 high | 16.8% | 2007-03-30 |
| CVE-2010-4227 EXP | The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbi… | Patch early | 10.0 high | 16.8% | 2011-02-25 |
| CVE-2012-2131 EXP | Multiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a… | Patch early | 7.5 high | 16.8% | 2012-04-24 |
| CVE-2020-5192 EXP | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validatin… | Patch early | 8.8 high | 16.8% | 2020-01-06 |
| CVE-2008-1558 EXP | Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and… | Patch early | 10.0 high | 16.8% | 2008-03-31 |
| CVE-2007-6454 EXP | Heap-based buffer overflow in the handshakeHTTP function in servhs.cpp in PeerCast 0.1217 and earlier, and SVN 344 and earlier, allows remote attacker… | Patch early | 10.0 high | 16.8% | 2007-12-20 |
| CVE-2014-4936 EXP | The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earl… | Patch early | 9.3 high | 16.8% | 2014-12-16 |
| CVE-2021-3291 EXP | Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting… | Patch early | 7.2 high | 16.8% | 2021-01-26 |
| CVE-2019-16758 EXP | In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2… | Patch early | 7.5 high | 16.8% | 2019-11-21 |
| CVE-2016-5680 EXP | Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authentica… | Patch early | 8.8 high | 16.8% | 2016-08-31 |
| CVE-2006-0323 EXP | Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Playe… | Patch early | 9.3 high | 16.7% | 2006-03-23 |
| CVE-2009-0263 EXP | Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1)… | Patch early | 10.0 high | 16.7% | 2009-01-23 |
| CVE-2016-8523 EXP | A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found. | Patch early | 8.8 high | 16.7% | 2018-02-15 |
| CVE-2009-0065 EXP | Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 al… | Patch early | 10.0 high | 16.7% | 2009-01-07 |
| CVE-2014-2087 EXP | Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8… | Patch early | 9.3 high | 16.7% | 2014-03-18 |
| CVE-2000-1221 EXP | The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the l… | Patch early | 10.0 high | 16.7% | 2000-01-08 |
| CVE-2009-3020 EXP | win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file… | Patch early | 7.1 high | 16.7% | 2009-08-31 |
| CVE-2022-2551 EXP | The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of th… | Patch early | 7.5 high | 16.7% | 2022-08-22 |
| CVE-2012-4412 EXP | Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial… | Patch early | 7.5 high | 16.7% | 2013-10-09 |
| CVE-2019-14378 EXP | ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment… | Patch early | 8.8 high | 16.7% | 2019-07-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt