CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
320,005 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-2674 EXP | Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attackers to read arbitrary files via… | Patch early | 7.5 high | 15.2% | 2018-03-19 |
| CVE-2011-3499 EXP | Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execut… | Patch early | 10.0 high | 15.2% | 2011-09-16 |
| CVE-2007-6682 EXP | Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary c… | Patch early | 7.5 high | 15.1% | 2008-01-17 |
| CVE-2012-4409 EXP | Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute ar… | Patch early | 6.8 medium | 15.1% | 2012-11-21 |
| CVE-2017-8644 EXP | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that… | Patch early | 4.3 medium | 15.1% | 2017-08-08 |
| CVE-2019-1019 EXP | A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerabi… | Patch early | 8.5 high | 15.1% | 2019-06-12 |
| CVE-2018-2636 EXP | Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security). Supported versions that are af… | Patch early | 8.1 high | 15.1% | 2018-01-18 |
| CVE-2010-4645 EXP | strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to… | Patch early | 5.0 medium | 15.1% | 2011-01-11 |
| CVE-2010-1533 EXP | Directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (d… | Patch early | 7.5 high | 15.1% | 2010-04-26 |
| CVE-2010-3150 EXP | Untrusted search path vulnerability in Adobe Premier Pro CS4 4.0.0 (314 (MC: 160820)) allows local users, and possibly remote attackers, to execute ar… | Patch early | 9.3 high | 15.1% | 2010-08-27 |
| CVE-2010-3151 EXP | Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers, to execute arbitrary code an… | Patch early | 9.3 high | 15.1% | 2010-08-27 |
| CVE-2013-1602 EXP | An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01,… | Patch early | 7.5 high | 15.1% | 2020-01-28 |
| CVE-2008-3795 EXP | Buffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long "message response." | Patch early | 10.0 high | 15.1% | 2008-08-27 |
| CVE-2010-3140 EXP | Untrusted search path vulnerability in Microsoft Windows Internet Communication Settings on Windows XP SP3 allows local users, and possibly remote att… | Patch early | 9.3 high | 15.1% | 2010-08-27 |
| CVE-2002-0163 EXP | Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a d… | Patch early | 7.5 high | 15.1% | 2002-03-26 |
| CVE-2008-2712 EXP | Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize… | Patch early | 9.3 high | 15% | 2008-06-16 |
| CVE-2008-1878 EXP | Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to… | Patch early | 7.5 high | 15% | 2008-04-17 |
| CVE-2002-0723 EXP | Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read… | Patch early | 7.5 high | 15% | 2002-09-24 |
| CVE-2002-1187 EXP | Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system v… | Patch early | 6.8 medium | 15% | 2002-12-11 |
| CVE-2009-1765 EXP | Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary… | Patch early | 6.8 medium | 15% | 2009-05-22 |
| CVE-2021-40378 EXP | An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from th… | Patch early | 8.1 high | 15% | 2021-09-01 |
| CVE-2018-0744 EXP | The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows… | Patch early | 7.0 high | 15% | 2018-01-04 |
| CVE-2000-0330 EXP | The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL… | Patch early | 7.6 high | 15% | 1999-11-12 |
| CVE-2010-1688 EXP | Stack-based buffer overflow in 2BrightSparks SyncBack Freeware 3.2.20.0, and possibly other versions before 3.2.21, allows user-assisted remote attack… | Patch early | 9.3 high | 15% | 2010-05-24 |
| CVE-2007-5158 EXP | The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a… | Patch early | 4.3 medium | 15% | 2007-10-01 |
| CVE-2012-0780 EXP | Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a di… | Patch early | 10.0 high | 15% | 2012-05-09 |
| CVE-2008-2950 EXP | The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constru… | Patch early | 7.5 high | 15% | 2008-07-07 |
| CVE-2025-5548 EXP | A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component NOOP Comman… | Patch early | 7.3 high | 15% | 2025-06-04 |
| CVE-2008-1307 EXP | Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29… | Patch early | 10.0 high | 15% | 2008-03-12 |
| CVE-2006-6602 EXP | explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a c… | Patch early | 4.3 medium | 15% | 2006-12-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt