CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,092 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
401,092 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-1213 EXP | Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via… | Patch early | 9.3 high | 33% | 2011-05-31 |
| CVE-2007-3068 EXP | Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long fi… | Patch early | 6.8 medium | 32.9% | 2007-06-06 |
| CVE-2016-4227 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… | Patch early | 8.8 high | 32.9% | 2016-07-13 |
| CVE-2016-4231 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.6… | Patch early | 8.8 high | 32.9% | 2016-07-13 |
| CVE-2012-1007 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the… | Patch early | 4.3 medium | 32.9% | 2012-02-07 |
| CVE-2018-19458 EXP | In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability t… | Patch early | 7.5 high | 32.9% | 2018-11-22 |
| CVE-2014-1799 EXP | Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 9.3 high | 32.9% | 2014-06-11 |
| CVE-2017-3241 EXP | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java… | Patch early | 9.0 critical | 32.8% | 2017-01-27 |
| CVE-2005-1979 EXP | Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "… | Patch early | 5.0 medium | 32.8% | 2005-10-12 |
| CVE-2010-4588 EXP | The WBEMSingleView.ocx ActiveX control 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier allows remote attackers to execute arbitrary… | Patch early | 9.3 high | 32.8% | 2010-12-23 |
| CVE-2008-3364 EXP | Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-De… | Patch early | 9.3 high | 32.8% | 2008-07-30 |
| CVE-2015-3137 EXP | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… | Patch early | 10.0 high | 32.8% | 2015-07-09 |
| CVE-2015-4430 EXP | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… | Patch early | 10.0 high | 32.8% | 2015-07-09 |
| CVE-2008-0871 EXP | Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long pa… | Patch early | 6.8 medium | 32.8% | 2008-02-21 |
| CVE-2026-4257 EXP | The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in al… | Patch early | 9.8 critical | 32.8% | 2026-03-30 |
| CVE-2022-31885 EXP | Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts. | Patch early | 9.8 critical | 32.8% | 2022-06-28 |
| CVE-2004-2434 EXP | Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace… | Patch early | 5.0 medium | 32.8% | 2004-12-31 |
| CVE-2013-3143 EXP | Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted… | Patch early | 9.3 high | 32.7% | 2013-07-10 |
| CVE-2019-0235 EXP | Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks. | Patch early | 8.8 high | 32.7% | 2020-04-30 |
| CVE-2005-1184 EXP | The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correc… | Patch early | 5.0 medium | 32.7% | 2005-05-02 |
| CVE-2008-4922 EXP | Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via… | Patch early | 9.3 high | 32.7% | 2008-11-04 |
| CVE-2007-2987 EXP | Multiple buffer overflows in certain ActiveX controls in sasatl.dll in Zenturi ProgramChecker allow remote attackers to execute arbitrary code via uns… | Patch early | 9.3 high | 32.7% | 2007-06-01 |
| CVE-2008-0803 EXP | Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 32.7% | 2008-02-15 |
| CVE-2008-5711 EXP | Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a… | Patch early | 9.3 high | 32.7% | 2008-12-24 |
| CVE-2008-2286 EXP | SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute… | Patch early | 7.5 high | 32.7% | 2008-05-18 |
| CVE-2017-2992 EXP | Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header. Successful exploitation… | Patch early | 8.8 high | 32.7% | 2017-02-15 |
| CVE-2021-37589 EXP | Virtua Cobranca before 12R allows SQL Injection on the login page. | Patch early | 7.5 high | 32.7% | 2022-06-07 |
| CVE-2012-5960 EXP | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… | Patch early | 10.0 high | 32.6% | 2013-01-31 |
| CVE-2009-3830 EXP | The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP… | Patch early | 5.0 medium | 32.6% | 2009-10-30 |
| CVE-2007-1644 EXP | The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or confi… | Patch early | 10.0 high | 32.6% | 2007-03-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt