CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,098 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
401,098 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-5232 EXP | Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services… | Patch early | 9.3 high | 32.2% | 2008-11-26 |
| CVE-2009-1568 EXP | Stack-based buffer overflow in ienipp.ocx in Novell iPrint Client 5.30, and possibly other versions before 5.32, allows remote attackers to execute ar… | Patch early | 9.3 high | 32.2% | 2009-12-08 |
| CVE-2017-7692 EXP | SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mish… | Patch early | 8.8 high | 32.2% | 2017-04-20 |
| CVE-2019-13024 EXP | Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using th… | Patch early | 8.8 high | 32.2% | 2019-07-01 |
| CVE-2009-3837 EXP | Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error message. | Patch early | 9.3 high | 32.1% | 2009-11-02 |
| CVE-2009-4588 EXP | Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft Awakening Web3D… | Patch early | 9.3 high | 32% | 2010-01-07 |
| CVE-2018-12827 EXP | Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | Patch early | 7.5 high | 32% | 2018-08-29 |
| CVE-2013-3174 EXP | DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows… | Patch early | 9.3 high | 32% | 2013-07-10 |
| CVE-2011-5170 EXP | Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u… | Patch early | 9.3 high | 32% | 2012-09-15 |
| CVE-2010-5193 EXP | Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx) in Viscom Image Viewe… | Patch early | 9.3 high | 32% | 2012-08-31 |
| CVE-2009-4498 EXP | The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request. | Patch early | 6.8 medium | 31.9% | 2009-12-31 |
| CVE-2006-1191 EXP | Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote… | Patch early | 4.0 medium | 31.9% | 2006-04-11 |
| CVE-2021-46378 EXP | DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download. | Patch early | 7.5 high | 31.9% | 2022-03-04 |
| CVE-2009-1029 EXP | Stack-based buffer overflow in POP Peeper 3.4.0.0 and earlier allows remote POP3 servers to execute arbitrary code via a long Date header, related to… | Patch early | 9.3 high | 31.8% | 2009-03-20 |
| CVE-2017-6026 EXP | A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.1… | Patch early | 9.1 critical | 31.8% | 2017-06-30 |
| CVE-2007-1559 EXP | Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via (1) unspec… | Patch early | 9.3 high | 31.8% | 2007-04-11 |
| CVE-2018-13415 EXP | In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.… | Patch early | 9.8 critical | 31.8% | 2018-08-13 |
| CVE-2018-7777 EXP | The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder softwar… | Patch early | 8.8 high | 31.8% | 2018-07-03 |
| CVE-2007-5511 EXP | SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to exec… | Patch early | 6.5 medium | 31.8% | 2007-10-17 |
| CVE-2006-1192 EXP | Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trus… | Patch early | 2.6 low | 31.7% | 2006-04-11 |
| CVE-2008-6898 EXP | Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote attackers to cause a denial o… | Patch early | 9.3 high | 31.7% | 2009-08-05 |
| CVE-2023-36355 EXP | TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows… | Patch early | 9.9 critical | 31.7% | 2023-06-22 |
| CVE-2019-6714 EXP | An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unaut… | Patch early | 9.8 critical | 31.7% | 2019-03-21 |
| CVE-2007-2244 EXP | Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code… | Patch early | 9.3 high | 31.7% | 2007-04-25 |
| CVE-2012-5613 EXP | MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who s… | Patch early | 6.0 medium | 31.7% | 2012-12-03 |
| CVE-2013-3120 EXP | Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch early | 9.3 high | 31.6% | 2013-06-12 |
| CVE-2015-8048 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… | Patch early | 10.0 high | 31.6% | 2015-12-10 |
| CVE-2015-8410 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… | Patch early | 10.0 high | 31.6% | 2015-12-10 |
| CVE-2015-8411 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… | Patch early | 10.0 high | 31.6% | 2015-12-10 |
| CVE-2015-8412 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 o… | Patch early | 10.0 high | 31.6% | 2015-12-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt