CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,941 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-02
400,941 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-5132 EXP | Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR S… | Patch early | 10.0 high | 50.7% | 2015-08-14 |
| CVE-2015-5133 EXP | Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR S… | Patch early | 10.0 high | 50.7% | 2015-08-14 |
| CVE-2007-4336 EXP | Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX control in DXTLIPI.DLL 6.0.2.827,… | Patch early | 4.3 medium | 50.7% | 2007-08-14 |
| CVE-2008-1562 EXP | The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via… | Patch early | 5.0 medium | 50.7% | 2008-03-31 |
| CVE-2004-0120 EXP | The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a den… | Patch early | 5.0 medium | 50.7% | 2004-06-01 |
| CVE-2010-0904 EXP | Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect integrity via unknown vectors. | Patch early | 5.0 medium | 50.6% | 2010-07-13 |
| CVE-2024-25735 EXP | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config… | Patch early | 9.1 critical | 50.6% | 2024-03-27 |
| CVE-2005-0553 EXP | Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers… | Patch early | 5.1 medium | 50.6% | 2005-05-02 |
| CVE-2011-3639 EXP | The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not pro… | Patch early | 4.3 medium | 50.6% | 2011-11-30 |
| CVE-2022-35919 EXP | MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized fo… | Patch early | 7.4 high | 50.6% | 2022-08-01 |
| CVE-2014-9308 EXP | Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin b… | Patch early | 6.5 medium | 50.6% | 2015-01-15 |
| CVE-2014-7146 EXP | The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or… | Patch early | 7.5 high | 50.6% | 2014-11-18 |
| CVE-2007-1567 EXP | Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary co… | Patch early | 10.0 high | 50.5% | 2007-03-21 |
| CVE-2001-1410 EXP | Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow… | Patch early | 5.0 medium | 50.5% | 2003-08-18 |
| CVE-2013-1884 EXP | The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault… | Patch early | 5.0 medium | 50.5% | 2013-05-02 |
| CVE-2018-19524 EXP | An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 dev… | Patch early | 9.8 critical | 50.5% | 2019-03-21 |
| CVE-2009-4655 EXP | The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via… | Patch early | 7.5 high | 50.5% | 2010-02-26 |
| CVE-2016-3303 EXP | The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Vie… | Patch early | 7.8 high | 50.5% | 2016-08-09 |
| CVE-2016-3304 EXP | The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Vie… | Patch early | 7.8 high | 50.5% | 2016-08-09 |
| CVE-2017-0108 EXP | The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meetin… | Patch early | 7.8 high | 50.5% | 2017-03-17 |
| CVE-2007-6016 EXP | Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Serv… | Patch early | 9.3 high | 50.4% | 2008-02-29 |
| CVE-2017-8594 EXP | Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute arbitrary code in the context… | Patch early | 7.5 high | 50.4% | 2017-07-11 |
| CVE-2017-8751 EXP | Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsof… | Patch early | 7.5 high | 50.4% | 2017-09-13 |
| CVE-2002-0061 EXP | Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe… | Patch early | 7.5 high | 50.4% | 2002-03-21 |
| CVE-2012-2336 EXP | sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings… | Patch early | 5.0 medium | 50.3% | 2012-05-11 |
| CVE-2014-7285 EXP | The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by… | Patch early | 6.5 medium | 50.3% | 2014-12-17 |
| CVE-2017-16720 EXP | A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the t… | Patch early | 9.8 critical | 50.3% | 2018-01-05 |
| CVE-2017-6465 EXP | Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; howeve… | Patch early | 9.8 critical | 50.3% | 2017-03-10 |
| CVE-2015-5127 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199… | Patch early | 10.0 high | 50.3% | 2015-08-14 |
| CVE-2015-5130 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199… | Patch early | 10.0 high | 50.3% | 2015-08-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt