CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,092 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
319,698 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-2758 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2759 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2760 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2761 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2763 EXP | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2764 EXP | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2765 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2766 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2767 EXP | Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted w… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2768 EXP | Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2769 EXP | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2770 EXP | Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web sit… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2771 EXP | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2772 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2014-2773 EXP | Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft… | Patch early | 9.3 high | 20.5% | 2014-06-11 |
| CVE-2002-1374 EXP | The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack usi… | Patch early | 7.5 high | 20.5% | 2002-12-23 |
| CVE-2016-3717 EXP | The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image. | Patch early | 5.5 medium | 20.4% | 2016-05-05 |
| CVE-2005-3862 EXP | Buffer overflow in unalz before 0.53 allows remote attackers to execute arbitrary code via long file names in ALZ archives. | Patch early | 7.5 high | 20.4% | 2005-11-29 |
| CVE-2009-3244 EXP | Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial… | Patch early | 9.3 high | 20.4% | 2009-09-18 |
| CVE-2013-1451 EXP | Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, doe… | Patch early | 4.0 medium | 20.4% | 2013-01-29 |
| CVE-2006-4812 EXP | Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP func… | Patch early | 10.0 high | 20.4% | 2006-10-10 |
| CVE-2017-3068 EXP | Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding engine. Successful… | Patch early | 8.8 high | 20.4% | 2017-05-09 |
| CVE-2010-0740 EXP | The ssl3_get_record function in ssl/s3_pkt.c in OpenSSL 0.9.8f through 0.9.8m allows remote attackers to cause a denial of service (crash) via a malfo… | Patch early | 5.0 medium | 20.4% | 2010-03-26 |
| CVE-2005-0551 EXP | Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and W… | Patch early | 10.0 high | 20.3% | 2005-05-02 |
| CVE-2014-5258 EXP | Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files… | Patch early | 4.0 medium | 20.3% | 2014-11-06 |
| CVE-2010-0816 EXP | Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 an… | Patch early | 9.3 high | 20.3% | 2010-05-12 |
| CVE-2004-0791 EXP | Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a… | Patch early | 5.0 medium | 20.3% | 2005-04-12 |
| CVE-2006-6332 EXP | Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execute arbitrary code via unspecifi… | Patch early | 7.5 high | 20.3% | 2006-12-10 |
| CVE-2009-2694 EXP | The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5… | Patch early | 10.0 high | 20.3% | 2009-08-21 |
| CVE-2012-0207 EXP | The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero… | Patch early | 7.5 high | 20.3% | 2012-05-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt