CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,599 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
402,599 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-1128 EXP | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerabili… | Patch early | 8.8 high | 16.9% | 2019-07-15 |
| CVE-2017-1002008 EXP | Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-membe… | Patch early | 9.8 critical | 16.9% | 2017-09-14 |
| CVE-2018-7669 EXP | An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory… | Patch early | 7.5 high | 16.9% | 2018-04-27 |
| CVE-2010-1531 EXP | Directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a .. (d… | Patch early | 7.5 high | 16.9% | 2010-04-26 |
| CVE-2015-3440 EXP | Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 16.9% | 2015-08-03 |
| CVE-2008-0250 EXP | Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with… | Patch early | 9.3 high | 16.9% | 2008-01-12 |
| CVE-2013-2678 EXP | Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive informati… | Patch early | 8.1 high | 16.9% | 2020-02-04 |
| CVE-2010-1345 EXP | Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary fil… | Patch early | 5.0 medium | 16.9% | 2010-04-09 |
| CVE-2014-2595 EXP | Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obt… | Patch early | 9.8 critical | 16.9% | 2020-02-12 |
| CVE-2014-0030 EXP | The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. | Patch early | 9.8 critical | 16.9% | 2017-10-10 |
| CVE-2012-3282 EXP | Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code v… | Patch early | 10.0 high | 16.9% | 2013-02-06 |
| CVE-2008-5177 EXP | Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (1) execute arbitrary code on a Linux platfo… | Patch early | 10.0 high | 16.9% | 2008-11-20 |
| CVE-2006-3772 EXP | PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass security restrictions and obtain a… | Patch early | 5.1 medium | 16.8% | 2006-07-24 |
| CVE-2008-3362 EXP | Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to exec… | Patch early | 10.0 high | 16.8% | 2008-07-30 |
| CVE-2010-3152 EXP | Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions allows local users, and possi… | Patch early | 9.3 high | 16.8% | 2010-08-27 |
| CVE-2007-1770 EXP | Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three t… | Patch early | 10.0 high | 16.8% | 2007-03-30 |
| CVE-2019-8042 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 16.8% | 2019-08-20 |
| CVE-2019-8197 EXP | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | Patch early | 9.8 critical | 16.8% | 2019-10-17 |
| CVE-2020-26567 EXP | An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any ac… | Patch early | 5.5 medium | 16.8% | 2020-10-08 |
| CVE-2017-8535 EXP | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… | Patch early | 5.5 medium | 16.8% | 2017-05-26 |
| CVE-2017-8536 EXP | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… | Patch early | 5.5 medium | 16.8% | 2017-05-26 |
| CVE-2017-8537 EXP | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… | Patch early | 5.5 medium | 16.8% | 2017-05-26 |
| CVE-2010-4227 EXP | The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbi… | Patch early | 10.0 high | 16.8% | 2011-02-25 |
| CVE-2012-2131 EXP | Multiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a… | Patch early | 7.5 high | 16.8% | 2012-04-24 |
| CVE-2020-5192 EXP | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validatin… | Patch early | 8.8 high | 16.8% | 2020-01-06 |
| CVE-2008-1558 EXP | Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and… | Patch early | 10.0 high | 16.8% | 2008-03-31 |
| CVE-2007-6454 EXP | Heap-based buffer overflow in the handshakeHTTP function in servhs.cpp in PeerCast 0.1217 and earlier, and SVN 344 and earlier, allows remote attacker… | Patch early | 10.0 high | 16.8% | 2007-12-20 |
| CVE-1999-0224 EXP | Denial of service in Windows NT messenger service through a long username. | Patch early | 5.0 medium | 16.8% | 1999-07-23 |
| CVE-2018-0494 EXP | GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line. | Patch early | 6.5 medium | 16.8% | 2018-05-06 |
| CVE-2014-4936 EXP | The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earl… | Patch early | 9.3 high | 16.8% | 2014-12-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt