CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,590 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
320,083 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-3805 EXP | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2)… | Patch early | 10.0 high | 13.1% | 2014-06-13 |
| CVE-2016-0049 EXP | Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows… | Patch early | 6.2 medium | 13.1% | 2016-02-10 |
| CVE-2015-2842 EXP | Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAutoDial GoAdmin CE 3.x before 3… | Patch early | 10.0 high | 13.1% | 2015-05-12 |
| CVE-2006-0147 EXP | Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis,… | Patch early | 7.5 high | 13.1% | 2006-01-09 |
| CVE-2007-2645 EXP | Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted remote attackers to cause a de… | Patch early | 9.3 high | 13.1% | 2007-05-14 |
| CVE-2019-1144 EXP | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succes… | Patch early | 8.8 high | 13.1% | 2019-08-14 |
| CVE-2019-1145 EXP | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succes… | Patch early | 8.8 high | 13.1% | 2019-08-14 |
| CVE-2019-1152 EXP | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succes… | Patch early | 8.8 high | 13.1% | 2019-08-14 |
| CVE-2011-3597 EXP | Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new co… | Patch early | 7.5 high | 13.1% | 2012-01-13 |
| CVE-2014-3997 EXP | SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Provide… | Patch early | 7.5 high | 13.1% | 2014-12-05 |
| CVE-2014-7192 EXP | Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer an… | Patch early | 10.0 high | 13% | 2014-12-11 |
| CVE-2021-20031 EXP | A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains… | Patch early | 6.1 medium | 13% | 2021-10-12 |
| CVE-2008-1709 EXP | Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with… | Patch early | 9.3 high | 13% | 2008-04-09 |
| CVE-2006-2860 EXP | PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter… | Patch early | 6.4 medium | 13% | 2006-06-06 |
| CVE-2015-1365 EXP | Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbi… | Patch early | 5.0 medium | 13% | 2015-01-27 |
| CVE-2002-0263 EXP | Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a multipart Conten… | Patch early | 7.5 high | 13% | 2002-05-29 |
| CVE-2010-2866 EXP | Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory… | Patch early | 9.3 high | 13% | 2010-08-26 |
| CVE-2010-2204 EXP | Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to cause a deni… | Patch early | 9.3 high | 13% | 2010-06-30 |
| CVE-2006-3581 EXP | Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via large (1)… | Patch early | 5.1 medium | 13% | 2006-07-13 |
| CVE-2017-8871 EXP | The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and C… | Patch early | 6.5 medium | 13% | 2017-06-12 |
| CVE-2002-0289 EXP | Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request. | Patch early | 5.0 medium | 13% | 2002-05-31 |
| CVE-2010-1952 EXP | Directory traversal vulnerability in the BeeHeard (com_beeheard) and BeeHeard Lite (com_beeheardlite) component 1.0 for Joomla! allows remote attacker… | Patch early | 7.5 high | 13% | 2010-05-19 |
| CVE-2011-2780 EXP | Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) i… | Patch early | 5.0 medium | 13% | 2011-07-19 |
| CVE-2006-1776 EXP | PHP remote file inclusion vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 13% | 2006-04-13 |
| CVE-2008-2303 EXP | Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a d… | Patch early | 10.0 high | 13% | 2008-07-14 |
| CVE-2000-0622 EXP | Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL… | Patch early | 10.0 high | 13% | 2000-07-19 |
| CVE-2013-2009 EXP | WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution | Patch early | 8.8 high | 13% | 2020-02-07 |
| CVE-2012-3571 EXP | ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) vi… | Patch early | 6.1 medium | 13% | 2012-07-25 |
| CVE-2012-0985 EXP | Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard… | Patch early | 9.3 high | 13% | 2012-06-07 |
| CVE-2008-1802 EXP | Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitrary code via a Remote Desktop… | Patch early | 9.3 high | 13% | 2008-05-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt