CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,075 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
186,447 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-0835 EXP | MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead o… | Patch early | 7.5 high | 22.4% | 2004-11-03 |
| CVE-2017-3106 EXP | Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation co… | Patch early | 8.8 high | 22.3% | 2017-08-11 |
| CVE-2016-3987 EXP | The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefa… | Patch early | 9.8 critical | 22.3% | 2016-04-12 |
| CVE-2014-2782 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 22.3% | 2014-06-19 |
| CVE-2013-0662 EXP | Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute a… | Patch early | 9.3 high | 22.3% | 2014-04-01 |
| CVE-2010-1717 EXP | Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitrary files and… | Patch early | 7.5 high | 22.3% | 2010-05-04 |
| CVE-2017-3077 EXP | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful exploitatio… | Patch early | 9.8 critical | 22.3% | 2017-06-20 |
| CVE-2008-2469 EXP | Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitr… | Patch early | 10.0 high | 22.3% | 2008-10-23 |
| CVE-2006-7066 EXP | Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, d… | Patch early | 7.1 high | 22.2% | 2007-03-02 |
| CVE-2011-2131 EXP | Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a den… | Patch early | 9.3 high | 22.2% | 2011-08-11 |
| CVE-2003-0899 EXP | Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '… | Patch early | 9.8 critical | 22.2% | 2003-11-03 |
| CVE-2008-0590 EXP | Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute… | Patch early | 9.0 high | 22.2% | 2008-02-05 |
| CVE-2006-2444 EXP | The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) vi… | Patch early | 7.8 high | 22.1% | 2006-05-25 |
| CVE-2006-4494 EXP | Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiat… | Patch early | 7.5 high | 22.1% | 2006-08-31 |
| CVE-2006-7206 EXP | Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and… | Patch early | 7.8 high | 22.1% | 2007-06-22 |
| CVE-2002-1179 EXP | Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digi… | Patch early | 7.5 high | 22.1% | 2002-10-28 |
| CVE-2019-8016 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 22% | 2019-08-20 |
| CVE-2022-4510 EXP | A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesyste… | Patch early | 7.8 high | 22% | 2023-01-26 |
| CVE-2013-3846 EXP | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (m… | Patch early | 9.3 high | 22% | 2013-12-29 |
| CVE-2017-3623 EXP | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are affected see n… | Patch early | 10.0 critical | 22% | 2017-04-24 |
| CVE-2018-19246 EXP | PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their… | Patch early | 7.5 high | 22% | 2018-11-13 |
| CVE-2003-0666 EXP | Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters… | Patch early | 7.5 high | 21.9% | 2003-10-20 |
| CVE-2020-10884 EXP | This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750… | Patch early | 8.8 high | 21.9% | 2020-03-25 |
| CVE-2010-1938 EXP | Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE… | Patch early | 9.3 high | 21.9% | 2010-05-28 |
| CVE-2007-3927 EXP | Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in… | Patch early | 10.0 high | 21.9% | 2007-07-21 |
| CVE-2012-0016 EXP | Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, and 4 allows local users to gai… | Patch early | 9.3 high | 21.9% | 2012-03-13 |
| CVE-2015-3302 EXP | The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers… | Patch early | 7.5 high | 21.8% | 2017-12-29 |
| CVE-2018-8057 EXP | A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/ad… | Patch early | 9.8 critical | 21.8% | 2018-03-11 |
| CVE-2017-2985 EXP | Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class. Successful… | Patch early | 8.8 high | 21.8% | 2017-02-15 |
| CVE-2017-6542 EXP | The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent proto… | Patch early | 9.8 critical | 21.8% | 2017-03-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt