CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,098 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
186,459 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-3862 EXP | Buffer overflow in unalz before 0.53 allows remote attackers to execute arbitrary code via long file names in ALZ archives. | Patch early | 7.5 high | 20.4% | 2005-11-29 |
| CVE-2009-3244 EXP | Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial… | Patch early | 9.3 high | 20.4% | 2009-09-18 |
| CVE-2006-4812 EXP | Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP func… | Patch early | 10.0 high | 20.4% | 2006-10-10 |
| CVE-2017-3068 EXP | Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding engine. Successful… | Patch early | 8.8 high | 20.4% | 2017-05-09 |
| CVE-2022-31125 EXP | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauth… | Patch early | 10.0 critical | 20.3% | 2022-07-06 |
| CVE-2005-0551 EXP | Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and W… | Patch early | 10.0 high | 20.3% | 2005-05-02 |
| CVE-2010-0816 EXP | Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 an… | Patch early | 9.3 high | 20.3% | 2010-05-12 |
| CVE-2006-6332 EXP | Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execute arbitrary code via unspecifi… | Patch early | 7.5 high | 20.3% | 2006-12-10 |
| CVE-2009-2694 EXP | The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5… | Patch early | 10.0 high | 20.3% | 2009-08-21 |
| CVE-2021-27828 EXP | SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavi… | Patch early | 9.1 critical | 20.3% | 2021-06-01 |
| CVE-2012-0207 EXP | The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero… | Patch early | 7.5 high | 20.3% | 2012-05-17 |
| CVE-2014-1815 EXP | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 20.3% | 2014-05-14 |
| CVE-2018-13416 EXP | In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) att… | Patch early | 9.8 critical | 20.2% | 2018-08-03 |
| CVE-2010-1039 EXP | Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.3… | Patch early | 10.0 high | 20.2% | 2010-05-20 |
| CVE-2019-0573 EXP | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Ser… | Patch early | 7.8 high | 20.1% | 2019-01-08 |
| CVE-2006-3124 EXP | Buffer overflow in the HTTP header parsing in Streamripper before 1.61.26 allows remote attackers to cause a denial of service and possibly execute ar… | Patch early | 7.5 high | 20.1% | 2006-08-26 |
| CVE-2006-4138 EXP | Multiple unspecified vulnerabilities in Microsoft Windows Help File viewer (winhlp32.exe) allow user-assisted attackers to execute arbitrary code via… | Patch early | 7.6 high | 20.1% | 2006-08-14 |
| CVE-2018-5973 EXP | SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryI… | Patch early | 9.8 critical | 20.1% | 2018-01-25 |
| CVE-2011-1271 EXP | The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle expressi… | Patch early | 7.7 high | 20.1% | 2011-05-10 |
| CVE-2012-3456 EXP | Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and ea… | Patch early | 7.5 high | 20.1% | 2012-08-20 |
| CVE-2004-0213 EXP | Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system… | Patch early | 7.8 high | 20.1% | 2004-08-06 |
| CVE-2018-12589 EXP | Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working directory. | Patch early | 7.8 high | 20.1% | 2018-06-28 |
| CVE-2010-3187 EXP | Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command. | Patch early | 10.0 high | 20% | 2010-08-30 |
| CVE-2006-6652 EXP | Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X… | Patch early | 9.0 high | 20% | 2006-12-20 |
| CVE-2009-4462 EXP | Stack-based buffer overflow in the NetBiterConfig utility (NetBiterConfig.exe) 1.3.0 for Intellicom NetBiter WebSCADA allows remote attackers to execu… | Patch early | 10.0 high | 20% | 2009-12-30 |
| CVE-2014-2775 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 20% | 2014-06-11 |
| CVE-2010-0359 EXP | Buffer overflow in the SSLv2 support in Zeus Web Server before 4.3r5 allows remote attackers to cause a denial of service (daemon crash) or possibly e… | Patch early | 10.0 high | 20% | 2010-01-20 |
| CVE-2025-49619 EXP | Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block.… | Patch early | 8.5 high | 20% | 2025-06-07 |
| CVE-2010-2305 EXP | Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote attackers to execute arbitrar… | Patch early | 9.3 high | 20% | 2010-06-16 |
| CVE-2008-1765 EXP | Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically pro… | Patch early | 9.3 high | 20% | 2008-04-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt