CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,556 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
320,600 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-1199 EXP | Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and… | Patch early | 9.3 high | 11.4% | 2010-06-24 |
| CVE-2007-2714 EXP | Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2, a WordPress plugin, has unknown impact and attack vectors. | Patch early | 10.0 high | 11.4% | 2007-05-16 |
| CVE-2020-24365 EXP | An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenti… | Patch early | 8.8 high | 11.4% | 2020-09-24 |
| CVE-2010-1056 EXP | Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and exe… | Patch early | 6.8 medium | 11.4% | 2010-03-23 |
| CVE-2012-5627 EXP | Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the… | Patch early | 4.0 medium | 11.4% | 2013-10-01 |
| CVE-2007-0134 EXP | Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is su… | Patch early | 7.5 high | 11.4% | 2007-01-09 |
| CVE-2003-0276 EXP | Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request wit… | Patch early | 5.0 medium | 11.4% | 2003-06-16 |
| CVE-2005-0859 EXP | PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlin… | Patch early | 7.5 high | 11.4% | 2005-05-02 |
| CVE-2020-14945 EXP | A privilege escalation vulnerability exists within Global RADAR BSA Radar 1.6.7234.24750 and earlier that allows an authenticated, low-privileged user… | Patch early | 8.8 high | 11.4% | 2020-06-22 |
| CVE-2004-1304 EXP | Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file. | Patch early | 10.0 high | 11.4% | 2005-01-10 |
| CVE-2000-0506 EXP | The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to pr… | Patch early | 10.0 high | 11.4% | 2000-06-09 |
| CVE-2006-5295 EXP | Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service crash) via a crafted Compress… | Patch early | 5.0 medium | 11.4% | 2006-10-16 |
| CVE-2019-16112 EXP | TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManag… | Patch early | 8.8 high | 11.4% | 2020-05-13 |
| CVE-2012-0551 EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE 7 update 4 and earlier and 6 update 32 and earlier, and the GlassFis… | Patch early | 5.8 medium | 11.4% | 2012-05-03 |
| CVE-2018-11492 EXP | ASUS HG100 devices allow denial of service via an IPv4 packet flood. | Patch early | 7.5 high | 11.4% | 2018-08-10 |
| CVE-2007-6327 EXP | Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attackers to execute arbitrary code… | Patch early | 7.5 high | 11.4% | 2007-12-13 |
| CVE-2019-15889 EXP | The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_d… | Patch early | 6.1 medium | 11.4% | 2019-09-03 |
| CVE-2019-6989 EXP | TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. By sending special… | Patch early | 8.8 high | 11.4% | 2019-06-06 |
| CVE-2008-2745 EXP | Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows remote attackers to execute ar… | Patch early | 9.3 high | 11.4% | 2008-06-17 |
| CVE-2016-2210 EXP | Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (… | Patch early | 7.3 high | 11.4% | 2016-06-30 |
| CVE-2003-0487 EXP | Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code… | Patch early | 7.5 high | 11.4% | 2003-08-07 |
| CVE-2001-0643 EXP | Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into… | Patch early | 5.0 medium | 11.4% | 2001-09-20 |
| CVE-2008-2044 EXP | includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of the true boolean literal, whi… | Patch early | 7.5 high | 11.4% | 2008-05-01 |
| CVE-2007-0816 EXP | The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to c… | Patch early | 5.0 medium | 11.4% | 2007-02-07 |
| CVE-2015-3081 EXP | Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, A… | Patch early | 4.3 medium | 11.4% | 2015-05-13 |
| CVE-2007-5925 EXP | The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to… | Patch early | 4.0 medium | 11.4% | 2007-11-10 |
| CVE-2013-6877 EXP | Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote attackers to e… | Patch early | 9.3 high | 11.3% | 2013-12-19 |
| CVE-2016-1608 EXP | vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary comm… | Patch early | 8.8 high | 11.3% | 2016-08-01 |
| CVE-2010-4278 EXP | operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters… | Patch early | 9.0 high | 11.3% | 2010-12-02 |
| CVE-2003-0108 EXP | isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP pa… | Patch early | 5.0 medium | 11.3% | 2003-03-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt