CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,074 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
149,744 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-3149 EXP | Untrusted search path vulnerability in Adobe Device Central CS5 3.0.0(376), 3.0.1.0 (3027), and probably other versions allows local users, and possib… | Patch early | 9.3 high | 13.6% | 2010-08-27 |
| CVE-2010-3153 EXP | Untrusted search path vulnerability in Adobe InDesign CS4 6.0, InDesign CS5 7.0.2 and earlier, Adobe InDesign Server CS5 7.0.2 and earlier, and Adobe… | Patch early | 9.3 high | 13.6% | 2010-08-27 |
| CVE-2008-4310 EXP | httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CP… | Patch early | 7.8 high | 13.6% | 2008-12-09 |
| CVE-2004-2425 EXP | Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and poss… | Patch early | 7.5 high | 13.5% | 2004-12-31 |
| CVE-2007-1357 EXP | The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service… | Patch early | 7.8 high | 13.5% | 2007-04-11 |
| CVE-2007-1685 EXP | Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a de… | Patch early | 10.0 high | 13.5% | 2007-06-08 |
| CVE-2007-5467 EXP | Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long… | Patch early | 10.0 high | 13.5% | 2007-10-15 |
| CVE-2002-1048 EXP | HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the… | Patch early | 7.5 high | 13.5% | 2002-10-04 |
| CVE-2019-8565 EXP | A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able… | Patch early | 7.0 high | 13.5% | 2019-12-18 |
| CVE-2008-0964 EXP | Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote… | Patch early | 9.3 high | 13.5% | 2008-08-08 |
| CVE-2010-0972 EXP | Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrar… | Patch early | 7.5 high | 13.5% | 2010-03-16 |
| CVE-2018-6383 EXP | Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extensio… | Patch early | 8.8 high | 13.5% | 2018-01-29 |
| CVE-2019-6967 EXP | AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF. | Patch early | 8.8 high | 13.5% | 2019-03-21 |
| CVE-2006-1618 EXP | Format string vulnerability in the (1) Con_message and (2) conPrintf functions in con_main.c in Doomsday engine 1.8.6 allows remote attackers to execu… | Patch early | 7.5 high | 13.5% | 2006-04-05 |
| CVE-2019-9581 EXP | phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP… | Patch early | 8.8 high | 13.5% | 2019-03-06 |
| CVE-2017-6444 EXP | The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows r… | Patch early | 7.5 high | 13.5% | 2017-03-12 |
| CVE-2000-0941 EXP | Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter. | Patch early | 10.0 high | 13.5% | 2000-12-19 |
| CVE-2001-0021 EXP | MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter. | Patch early | 10.0 high | 13.5% | 2001-02-16 |
| CVE-2007-1536 EXP | Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file th… | Patch early | 9.3 high | 13.5% | 2007-03-20 |
| CVE-2017-3064 EXP | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline. Successful exploi… | Patch early | 7.8 high | 13.5% | 2017-04-12 |
| CVE-2018-0709 EXP | Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitra… | Patch early | 8.8 high | 13.4% | 2018-07-17 |
| CVE-2008-3956 EXP | orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute… | Patch early | 9.3 high | 13.4% | 2008-09-11 |
| CVE-2008-3732 EXP | Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (applicat… | Patch early | 9.3 high | 13.4% | 2008-08-20 |
| CVE-2011-1944 EXP | Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers… | Patch early | 9.3 high | 13.4% | 2011-09-02 |
| CVE-2019-17424 EXP | A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewa… | Patch early | 7.8 high | 13.4% | 2019-10-22 |
| CVE-2016-2278 EXP | Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administ… | Patch early | 7.2 high | 13.4% | 2016-03-02 |
| CVE-2013-4787 EXP | Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrar… | Patch early | 9.3 high | 13.4% | 2013-07-09 |
| CVE-2019-10863 EXP | A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file wit… | Patch early | 7.2 high | 13.4% | 2019-04-04 |
| CVE-2019-8043 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 7.5 high | 13.4% | 2019-08-20 |
| CVE-2011-2628 EXP | Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service… | Patch early | 10.0 high | 13.4% | 2011-07-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt