CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,084 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
319,691 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-0590 EXP | Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute… | Patch early | 9.0 high | 22.2% | 2008-02-05 |
| CVE-2001-0137 EXP | Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file n… | Patch early | 5.1 medium | 22.2% | 2001-03-12 |
| CVE-2011-1669 EXP | Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary fil… | Patch early | 5.0 medium | 22.2% | 2011-04-10 |
| CVE-2006-2444 EXP | The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) vi… | Patch early | 7.8 high | 22.1% | 2006-05-25 |
| CVE-2006-4494 EXP | Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiat… | Patch early | 7.5 high | 22.1% | 2006-08-31 |
| CVE-2006-7206 EXP | Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and… | Patch early | 7.8 high | 22.1% | 2007-06-22 |
| CVE-2008-6482 EXP | PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is e… | Patch early | 6.8 medium | 22.1% | 2009-03-18 |
| CVE-2002-1179 EXP | Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digi… | Patch early | 7.5 high | 22.1% | 2002-10-28 |
| CVE-2010-3325 EXP | Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in Cascading Style Sheets (CSS) documents, which allow… | Patch early | 4.3 medium | 22% | 2010-10-13 |
| CVE-2017-0120 EXP | Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive informatio… | Patch early | 4.3 medium | 22% | 2017-03-17 |
| CVE-2012-1858 EXP | The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does n… | Patch early | 4.3 medium | 22% | 2012-06-12 |
| CVE-2022-4510 EXP | A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesyste… | Patch early | 7.8 high | 22% | 2023-01-26 |
| CVE-2002-0386 EXP | The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash)… | Patch early | 5.0 medium | 22% | 2002-11-04 |
| CVE-2006-6296 EXP | The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and e… | Patch early | 6.1 medium | 22% | 2006-12-05 |
| CVE-2013-3846 EXP | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (m… | Patch early | 9.3 high | 22% | 2013-12-29 |
| CVE-2001-1244 EXP | Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment s… | Patch early | 5.0 medium | 22% | 2001-07-07 |
| CVE-2018-19246 EXP | PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their… | Patch early | 7.5 high | 22% | 2018-11-13 |
| CVE-2003-0666 EXP | Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters… | Patch early | 7.5 high | 21.9% | 2003-10-20 |
| CVE-2020-10884 EXP | This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750… | Patch early | 8.8 high | 21.9% | 2020-03-25 |
| CVE-2002-2164 EXP | Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link. | Patch early | 5.0 medium | 21.9% | 2002-12-31 |
| CVE-2010-1938 EXP | Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE… | Patch early | 9.3 high | 21.9% | 2010-05-28 |
| CVE-2007-3927 EXP | Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in… | Patch early | 10.0 high | 21.9% | 2007-07-21 |
| CVE-2012-0016 EXP | Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, and 4 allows local users to gai… | Patch early | 9.3 high | 21.9% | 2012-03-13 |
| CVE-2013-4341 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow rem… | Patch early | 4.3 medium | 21.9% | 2013-09-16 |
| CVE-2015-3302 EXP | The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers… | Patch early | 7.5 high | 21.8% | 2017-12-29 |
| CVE-2017-2985 EXP | Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class. Successful… | Patch early | 8.8 high | 21.8% | 2017-02-15 |
| CVE-2009-1493 EXP | The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers t… | Patch early | 6.8 medium | 21.8% | 2009-04-30 |
| CVE-2022-34047 EXP | An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/s… | Patch early | 7.5 high | 21.8% | 2022-07-20 |
| CVE-2005-1649 EXP | The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attackers to cause a denial of serv… | Patch early | 5.0 medium | 21.8% | 2005-05-18 |
| CVE-2007-4934 EXP | Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code via a URL in the PHPFFL_FILE_RO… | Patch early | 4.6 medium | 21.7% | 2007-09-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt