CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,178 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
149,776 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-3575 EXP | Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino 8.5.2 allows remote authenticated users to execute… | Patch early | 9.0 high | 10.5% | 2011-09-19 |
| CVE-2018-12520 EXP | An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This res… | Patch early | 8.1 high | 10.5% | 2018-07-05 |
| CVE-2006-0720 EXP | Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service (crash) and possibly execute… | Patch early | 7.6 high | 10.5% | 2006-02-23 |
| CVE-2002-0252 EXP | Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a response containing a long Content-T… | Patch early | 7.5 high | 10.5% | 2002-05-29 |
| CVE-2006-6478 EXP | Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a)… | Patch early | 7.5 high | 10.5% | 2006-12-12 |
| CVE-2006-0468 EXP | CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP mes… | Patch early | 7.5 high | 10.5% | 2006-01-30 |
| CVE-2000-0690 EXP | Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter. | Patch early | 10.0 high | 10.5% | 2000-10-20 |
| CVE-2008-4587 EXP | Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.61372) in Macrovision FLEXnet… | Patch early | 9.3 high | 10.5% | 2008-10-15 |
| CVE-2022-46552 EXP | D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter… | Patch early | 8.8 high | 10.5% | 2023-02-02 |
| CVE-2014-1632 EXP | htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter. | Patch early | 8.1 high | 10.5% | 2018-01-31 |
| CVE-1999-0018 EXP | Buffer overflow in statd allows root privileges. | Patch early | 10.0 high | 10.5% | 1997-12-05 |
| CVE-2003-1096 EXP | The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier fo… | Patch early | 10.0 high | 10.5% | 2003-12-31 |
| CVE-2017-2536 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. Th… | Patch early | 8.8 high | 10.5% | 2017-05-22 |
| CVE-2010-0167 EXP | The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before… | Patch early | 9.3 high | 10.5% | 2010-03-25 |
| CVE-2010-0317 EXP | Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a lar… | Patch early | 7.8 high | 10.5% | 2010-01-15 |
| CVE-2009-1019 EXP | Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remot… | Patch early | 7.5 high | 10.5% | 2009-07-14 |
| CVE-2008-4453 EXP | The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro… | Patch early | 9.3 high | 10.5% | 2008-10-06 |
| CVE-2007-5019 EXP | Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact… | Patch early | 10.0 high | 10.5% | 2007-09-20 |
| CVE-2009-1169 EXP | The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a den… | Patch early | 9.3 high | 10.5% | 2009-03-27 |
| CVE-1999-0148 EXP | The handler CGI program in IRIX allows arbitrary command execution. | Patch early | 7.5 high | 10.5% | 1997-09-01 |
| CVE-2007-2200 EXP | Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files vi… | Patch early | 10.0 high | 10.5% | 2007-04-24 |
| CVE-2020-35754 EXP | OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via t… | Patch early | 7.2 high | 10.5% | 2021-01-28 |
| CVE-2009-4663 EXP | Heap-based buffer overflow in the Quiksoft EasyMail Objects 6 ActiveX control allows remote attackers to execute arbitrary code via a long argument to… | Patch early | 9.3 high | 10.5% | 2010-03-03 |
| CVE-2008-0352 EXP | The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving th… | Patch early | 7.8 high | 10.4% | 2008-01-18 |
| CVE-2005-3591 EXP | Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause… | Patch early | 7.5 high | 10.4% | 2005-11-16 |
| CVE-2004-1256 EXP | Multiple buffer overflows in the (1) event_text and (2) event_specific functions in abc2midi 2004.12.04 allow remote attackers to execute arbitrary co… | Patch early | 10.0 high | 10.4% | 2005-01-10 |
| CVE-2004-1288 EXP | Buffer overflow in the parse_html function in o3read.c for o3read 0.0.3 allows remote attackers to execute arbitrary code via a crafted SXW file. | Patch early | 10.0 high | 10.4% | 2005-01-10 |
| CVE-2020-35737 EXP | In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidat… | Patch early | 7.5 high | 10.4% | 2020-12-30 |
| CVE-2007-0887 EXP | axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference a… | Patch early | 7.8 high | 10.4% | 2007-02-12 |
| CVE-2018-15685 EXP | GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true"… | Patch early | 8.1 high | 10.4% | 2018-08-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt