CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,178 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
186,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-15691 EXP | Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute a… | Patch early | 9.8 critical | 16.8% | 2018-08-30 |
| CVE-2016-5680 EXP | Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authentica… | Patch early | 8.8 high | 16.8% | 2016-08-31 |
| CVE-2006-0323 EXP | Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Playe… | Patch early | 9.3 high | 16.7% | 2006-03-23 |
| CVE-2009-0263 EXP | Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1)… | Patch early | 10.0 high | 16.7% | 2009-01-23 |
| CVE-2016-8523 EXP | A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found. | Patch early | 8.8 high | 16.7% | 2018-02-15 |
| CVE-2009-0065 EXP | Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 al… | Patch early | 10.0 high | 16.7% | 2009-01-07 |
| CVE-2014-2087 EXP | Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8… | Patch early | 9.3 high | 16.7% | 2014-03-18 |
| CVE-2000-1221 EXP | The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the l… | Patch early | 10.0 high | 16.7% | 2000-01-08 |
| CVE-2009-3020 EXP | win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file… | Patch early | 7.1 high | 16.7% | 2009-08-31 |
| CVE-2018-9843 EXP | The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialize… | Patch early | 9.8 critical | 16.7% | 2018-04-12 |
| CVE-2017-6182 EXP | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command… | Patch early | 9.8 critical | 16.7% | 2017-03-30 |
| CVE-2022-2551 EXP | The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of th… | Patch early | 7.5 high | 16.7% | 2022-08-22 |
| CVE-2012-4412 EXP | Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial… | Patch early | 7.5 high | 16.7% | 2013-10-09 |
| CVE-2019-14378 EXP | ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment… | Patch early | 8.8 high | 16.7% | 2019-07-29 |
| CVE-2017-17085 EXP | In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by val… | Patch early | 7.5 high | 16.7% | 2017-12-01 |
| CVE-2010-1280 EXP | Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 8.8 high | 16.6% | 2010-05-13 |
| CVE-2009-0490 EXP | Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions bef… | Patch early | 9.3 high | 16.6% | 2009-02-10 |
| CVE-2020-28337 EXP | A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via… | Patch early | 7.2 high | 16.6% | 2021-02-15 |
| CVE-2001-0400 EXP | nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address. | Patch early | 7.5 high | 16.6% | 2001-07-02 |
| CVE-2021-36711 EXP | WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled. | Patch early | 9.8 critical | 16.6% | 2022-07-16 |
| CVE-2020-15492 EXP | An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP p… | Patch early | 9.8 critical | 16.6% | 2020-07-23 |
| CVE-2003-0567 EXP | Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 pac… | Patch early | 7.8 high | 16.6% | 2003-08-18 |
| CVE-2017-6315 EXP | Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx. | Patch early | 9.8 critical | 16.6% | 2017-09-19 |
| CVE-2004-1898 EXP | Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long user… | Patch early | 10.0 high | 16.6% | 2004-12-31 |
| CVE-2016-1713 EXP | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.ph… | Patch early | 7.3 high | 16.6% | 2017-04-14 |
| CVE-2005-1526 EXP | PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the co… | Patch early | 7.5 high | 16.6% | 2005-06-22 |
| CVE-2009-0849 EXP | Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute arbitrary code on Linux platform… | Patch early | 7.5 high | 16.5% | 2009-03-09 |
| CVE-2006-1900 EXP | Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers… | Patch early | 7.6 high | 16.5% | 2006-04-20 |
| CVE-2016-4135 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 8.8 high | 16.5% | 2016-06-16 |
| CVE-2019-6974 EXP | In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading t… | Patch early | 8.1 high | 16.5% | 2019-02-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt