CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,014 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
319,644 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-4466 EXP | Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code… | Patch early | 6.8 medium | 30.9% | 2007-10-09 |
| CVE-2011-2755 EXP | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 30.9% | 2011-07-17 |
| CVE-2006-6665 EXP | Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute arbitrary code via a long file… | Patch early | 6.8 medium | 30.9% | 2006-12-20 |
| CVE-2017-2986 EXP | Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (FLV) codec. Successful exploita… | Patch early | 8.8 high | 30.9% | 2017-02-15 |
| CVE-2008-0470 EXP | A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method. | Patch early | 9.3 high | 30.9% | 2008-01-29 |
| CVE-2010-5081 EXP | Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code via a long URL in a .pls file. | Patch early | 9.3 high | 30.9% | 2011-12-25 |
| CVE-2003-1172 EXP | Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access ar… | Patch early | 5.0 medium | 30.8% | 2003-12-31 |
| CVE-2009-3214 EXP | Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code via a crafted Slideshow proje… | Patch early | 9.3 high | 30.8% | 2009-09-16 |
| CVE-2010-0017 EXP | Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle atta… | Patch early | 9.3 high | 30.8% | 2010-02-10 |
| CVE-2016-0974 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 o… | Patch early | 8.8 high | 30.8% | 2016-02-10 |
| CVE-2015-6168 EXP | Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microso… | Patch early | 9.3 high | 30.7% | 2015-12-09 |
| CVE-2011-0500 EXP | Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions; allows user-assisted remote a… | Patch early | 9.3 high | 30.7% | 2011-01-20 |
| CVE-2009-2650 EXP | Heap-based buffer overflow in Sorcerer Software MultiMedia Jukebox 4.0 Build 020124 allows remote attackers to cause a denial of service (application… | Patch early | 9.3 high | 30.7% | 2009-07-30 |
| CVE-2004-1602 EXP | ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to ident… | Patch early | 5.0 medium | 30.7% | 2004-10-15 |
| CVE-2002-2006 EXP | The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sens… | Patch early | 5.0 medium | 30.7% | 2002-12-31 |
| CVE-2024-55963 EXP | An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causi… | Patch early | 6.5 medium | 30.7% | 2025-03-26 |
| CVE-2010-1797 EXP | Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in Free… | Patch early | 9.3 high | 30.7% | 2010-08-16 |
| CVE-2021-29440 EXP | Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or… | Patch early | 8.4 high | 30.6% | 2021-04-13 |
| CVE-2009-4225 EXP | Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote attackers to execute arbitrary… | Patch early | 9.3 high | 30.6% | 2009-12-08 |
| CVE-2005-1383 EXP | The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_a… | Patch early | 7.5 high | 30.6% | 2005-05-03 |
| CVE-2011-3976 EXP | Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST c… | Patch early | 6.8 medium | 30.6% | 2011-10-04 |
| CVE-1999-1375 EXP | FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file… | Patch early | 5.0 medium | 30.5% | 1999-02-11 |
| CVE-2015-6131 EXP | Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers to execute arbitrary code via a… | Patch early | 9.3 high | 30.5% | 2015-12-09 |
| CVE-2014-4141 EXP | Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 30.5% | 2014-10-15 |
| CVE-2020-35749 EXP | Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress… | Patch early | 7.7 high | 30.5% | 2021-01-15 |
| CVE-2020-7384 EXP | Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbi… | Patch early | 7.0 high | 30.5% | 2020-10-29 |
| CVE-2021-25158 EXP | A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.… | Patch early | 5.9 medium | 30.5% | 2021-03-30 |
| CVE-2008-0392 EXP | Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .d… | Patch early | 9.3 high | 30.5% | 2008-01-23 |
| CVE-2025-24514 EXP | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to… | Patch early | 8.8 high | 30.5% | 2025-03-25 |
| CVE-2011-0419 EXP | Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apach… | Patch early | 4.3 medium | 30.4% | 2011-05-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt