CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,069 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
401,069 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-24629 EXP | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in… | Patch early | 9.8 critical | 37.2% | 2023-05-29 |
| CVE-2016-3074 EXP | Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentiall… | Patch early | 9.8 critical | 37.2% | 2016-04-26 |
| CVE-2014-8686 EXP | CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when t… | Patch early | 9.8 critical | 37.2% | 2017-09-19 |
| CVE-2013-3928 EXP | Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary cod… | Patch early | 9.3 high | 37.2% | 2014-03-11 |
| CVE-2000-0854 EXP | When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, whic… | Patch early | 10.0 high | 37.2% | 2000-11-14 |
| CVE-2016-1106 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.2% | 2016-05-11 |
| CVE-2004-0095 EXP | McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary c… | Patch early | 5.0 medium | 37.2% | 2004-02-17 |
| CVE-2018-14064 EXP | The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80. | Patch early | 9.8 critical | 37.2% | 2018-07-15 |
| CVE-2006-6723 EXP | The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large… | Patch early | 7.8 high | 37.2% | 2006-12-26 |
| CVE-2008-0423 EXP | Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[clas… | Patch early | 6.8 medium | 37.1% | 2008-01-23 |
| CVE-2009-0476 EXP | Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio components for .N… | Patch early | 9.3 high | 37% | 2009-02-08 |
| CVE-2015-8351 EXP | PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote au… | Patch early | 9.0 critical | 37% | 2017-09-11 |
| CVE-2002-0023 EXP | Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass som… | Patch early | 5.0 medium | 37% | 2002-03-08 |
| CVE-2014-7883 EXP | HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by… | Patch early | 5.0 medium | 37% | 2015-02-15 |
| CVE-2005-0582 EXP | Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code via a long filename in a PUTOLF… | Patch early | 10.0 high | 37% | 2005-05-02 |
| CVE-2016-3115 EXP | Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command… | Patch early | 6.4 medium | 37% | 2016-03-22 |
| CVE-2011-5165 EXP | Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to execute arbit… | Patch early | 9.3 high | 37% | 2012-09-15 |
| CVE-2018-11529 EXP | VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV fi… | Patch early | 8.0 high | 37% | 2018-07-11 |
| CVE-2007-1525 EXP | Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat… | Patch early | 6.8 medium | 37% | 2007-03-20 |
| CVE-2015-4624 EXP | Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens. | Patch early | 7.5 high | 37% | 2017-03-31 |
| CVE-2017-6019 EXP | An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests t… | Patch early | 7.5 high | 36.9% | 2017-04-07 |
| CVE-2012-5961 EXP | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… | Patch early | 10.0 high | 36.9% | 2013-01-31 |
| CVE-2012-5962 EXP | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… | Patch early | 10.0 high | 36.9% | 2013-01-31 |
| CVE-2012-5963 EXP | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… | Patch early | 10.0 high | 36.9% | 2013-01-31 |
| CVE-2012-5964 EXP | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… | Patch early | 10.0 high | 36.9% | 2013-01-31 |
| CVE-2012-5965 EXP | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… | Patch early | 10.0 high | 36.9% | 2013-01-31 |
| CVE-2008-1074 EXP | PHP remote file inclusion vulnerability in lib/head_auth.php in GROUP-E 1.6.41 allows remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 6.8 medium | 36.9% | 2008-02-29 |
| CVE-2007-3624 EXP | Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in the… | Patch early | 10.0 high | 36.8% | 2007-07-09 |
| CVE-2012-0201 EXP | Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote at… | Patch early | 9.3 high | 36.8% | 2012-03-02 |
| CVE-2007-6530 EXP | Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury… | Patch early | 9.3 high | 36.8% | 2007-12-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt