CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,092 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
401,092 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-0050 EXP | Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted w… | Patch early | 9.3 high | 33.5% | 2015-02-11 |
| CVE-2017-16885 EXP | Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Chang… | Patch early | 9.8 critical | 33.5% | 2018-01-12 |
| CVE-2008-2069 EXP | Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto:… | Patch early | 9.3 high | 33.4% | 2008-05-02 |
| CVE-2000-0673 EXP | The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoof… | Patch early | 5.0 medium | 33.4% | 2000-07-27 |
| CVE-2013-1306 EXP | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers a… | Patch early | 9.3 high | 33.4% | 2013-05-15 |
| CVE-2015-3124 EXP | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… | Patch early | 10.0 high | 33.4% | 2015-07-09 |
| CVE-2018-11094 EXP | An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasic… | Patch early | 9.8 critical | 33.4% | 2018-05-15 |
| CVE-2014-8682 EXP | Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arb… | Patch early | 7.5 high | 33.4% | 2014-11-21 |
| CVE-2008-0117 EXP | Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute… | Patch early | 9.3 high | 33.4% | 2008-03-11 |
| CVE-2011-1772 EXP | Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow… | Patch early | 2.6 low | 33.3% | 2011-05-13 |
| CVE-2002-0193 EXP | Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fi… | Patch early | 7.5 high | 33.3% | 2002-05-29 |
| CVE-2005-1980 EXP | Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transact… | Patch early | 5.0 medium | 33.3% | 2005-10-12 |
| CVE-2014-1766 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 33.3% | 2014-04-27 |
| CVE-2009-1394 EXP | Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed st… | Patch early | 9.3 high | 33.3% | 2009-06-26 |
| CVE-2009-1612 EXP | Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary… | Patch early | 9.3 high | 33.3% | 2009-05-11 |
| CVE-2019-15813 EXP | Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell. | Patch early | 8.8 high | 33.2% | 2019-09-04 |
| CVE-2025-1097 EXP | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be… | Patch early | 8.8 high | 33.2% | 2025-03-25 |
| CVE-2020-29607 EXP | A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "mana… | Patch early | 7.2 high | 33.2% | 2020-12-16 |
| CVE-2010-4321 EXP | Stack-based buffer overflow in an ActiveX control in ienipp.ocx in Novell iPrint Client 5.52 allows remote attackers to execute arbitrary code via a l… | Patch early | 9.3 high | 33.2% | 2010-12-30 |
| CVE-2015-3337 EXP | Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read… | Patch early | 4.3 medium | 33.2% | 2015-05-01 |
| CVE-2016-4226 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… | Patch early | 8.8 high | 33.1% | 2016-07-13 |
| CVE-2016-4228 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… | Patch early | 8.8 high | 33.1% | 2016-07-13 |
| CVE-2016-0801 EXP | The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to exe… | Patch early | 9.8 critical | 33.1% | 2016-02-07 |
| CVE-2021-45043 EXP | HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter. | Patch early | 7.5 high | 33.1% | 2021-12-15 |
| CVE-2012-2288 EXP | Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers t… | Patch early | 9.3 high | 33.1% | 2012-09-04 |
| CVE-2015-1376 EXP | pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write… | Patch early | 4.0 medium | 33.1% | 2015-01-28 |
| CVE-2017-6187 EXP | Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET re… | Patch early | 9.8 critical | 33.1% | 2017-02-22 |
| CVE-2018-14716 EXP | A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elemen… | Patch early | 7.5 high | 33% | 2018-08-06 |
| CVE-2007-4515 EXP | Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 all… | Patch early | 9.3 high | 33% | 2007-08-31 |
| CVE-2009-1028 EXP | Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file. | Patch early | 9.3 high | 33% | 2009-03-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt