CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,185 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
186,489 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-4177 EXP | Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to… | Patch early | 8.8 high | 17.6% | 2016-07-13 |
| CVE-2008-5191 EXP | Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) poll_id parameter to poll.… | Patch early | 7.5 high | 17.6% | 2008-11-21 |
| CVE-2022-4395 EXP | The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbit… | Patch early | 9.8 critical | 17.6% | 2023-01-30 |
| CVE-2011-2960 EXP | Heap-based buffer overflow in httpsvr.exe 6.0.5.3 in Sunway ForceControl 6.1 SP1, SP2, and SP3 allows remote attackers to cause a denial of service (c… | Patch early | 10.0 high | 17.6% | 2011-07-29 |
| CVE-2017-5135 EXP | Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. The Technicolor (formerly Cisco… | Patch early | 9.1 critical | 17.5% | 2017-04-27 |
| CVE-2018-1321 EXP | An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1… | Patch early | 7.2 high | 17.5% | 2018-03-20 |
| CVE-2014-0749 EXP | Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x through 2.… | Patch early | 10.0 high | 17.5% | 2014-05-16 |
| CVE-2017-12945 EXP | Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute a… | Patch early | 8.8 high | 17.5% | 2019-11-27 |
| CVE-2004-0393 EXP | Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string spec… | Patch early | 10.0 high | 17.4% | 2004-12-06 |
| CVE-2005-2308 EXP | The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute a… | Patch early | 7.5 high | 17.4% | 2005-07-19 |
| CVE-2016-1077 EXP | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 17.4% | 2016-05-11 |
| CVE-2017-7240 EXP | An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and i… | Patch early | 7.5 high | 17.4% | 2017-03-24 |
| CVE-2002-1850 EXP | mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by cau… | Patch early | 7.5 high | 17.4% | 2002-12-31 |
| CVE-2020-13448 EXP | QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via comma… | Patch early | 8.8 high | 17.4% | 2020-06-01 |
| CVE-2023-26602 EXP | ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmp… | Patch early | 9.8 critical | 17.4% | 2023-02-26 |
| CVE-2006-2811 EXP | Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the ba… | Patch early | 7.5 high | 17.4% | 2006-06-05 |
| CVE-2019-6706 EXP | Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a de… | Patch early | 7.5 high | 17.4% | 2019-01-23 |
| CVE-2021-24040 EXP | Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input,… | Patch early | 9.8 critical | 17.4% | 2021-09-10 |
| CVE-2009-4637 EXP | FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-b… | Patch early | 10.0 high | 17.4% | 2010-02-10 |
| CVE-2021-24786 EXP | The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statemen… | Patch early | 7.2 high | 17.3% | 2022-01-03 |
| CVE-2019-12185 EXP | eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execu… | Patch early | 8.8 high | 17.3% | 2019-05-20 |
| CVE-2017-5447 EXP | An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an att… | Patch early | 9.1 critical | 17.3% | 2018-06-11 |
| CVE-2018-19908 EXP | An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to constru… | Patch early | 8.8 high | 17.3% | 2018-12-06 |
| CVE-2007-6681 EXP | Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle i… | Patch early | 7.5 high | 17.3% | 2008-01-17 |
| CVE-2019-6543 EXP | AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update.… | Patch early | 9.8 critical | 17.3% | 2019-02-13 |
| CVE-2003-1030 EXP | Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to… | Patch early | 7.5 high | 17.3% | 2004-02-17 |
| CVE-2017-5404 EXP | A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This… | Patch early | 9.8 critical | 17.3% | 2018-06-11 |
| CVE-2019-10678 EXP | Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options. | Patch early | 7.5 high | 17.3% | 2019-03-31 |
| CVE-2004-1119 EXP | Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arbitrary co… | Patch early | 10.0 high | 17.3% | 2005-01-10 |
| CVE-2018-13859 EXP | MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, allow unauthorized remote attacke… | Patch early | 9.8 critical | 17.2% | 2018-07-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt