CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,831 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
205,622 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-2345 EXP | Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbit… | Patch early | 9.8 critical | 51.2% | 2016-03-17 |
| CVE-2008-1365 EXP | Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, al… | Patch early | 6.4 medium | 51.1% | 2008-03-17 |
| CVE-2000-0665 EXP | GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username. | Patch early | 5.0 medium | 51% | 2000-07-17 |
| CVE-2000-0869 EXP | The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPF… | Patch early | 5.0 medium | 51% | 2000-11-14 |
| CVE-2018-1217 EXP | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affec… | Patch early | 9.8 critical | 50.9% | 2018-04-09 |
| CVE-2021-34646 EXP | Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_ve… | Patch early | 9.8 critical | 50.9% | 2021-08-30 |
| CVE-2017-3548 EXP | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions… | Patch early | 6.5 medium | 50.8% | 2017-04-24 |
| CVE-2015-8256 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras. | Patch early | 6.1 medium | 50.8% | 2017-04-17 |
| CVE-2019-12518 EXP | Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability. | Patch early | 9.8 critical | 50.7% | 2019-12-02 |
| CVE-2007-4336 EXP | Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX control in DXTLIPI.DLL 6.0.2.827,… | Patch early | 4.3 medium | 50.7% | 2007-08-14 |
| CVE-2008-1562 EXP | The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via… | Patch early | 5.0 medium | 50.7% | 2008-03-31 |
| CVE-2004-0120 EXP | The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a den… | Patch early | 5.0 medium | 50.7% | 2004-06-01 |
| CVE-2010-0904 EXP | Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect integrity via unknown vectors. | Patch early | 5.0 medium | 50.6% | 2010-07-13 |
| CVE-2024-25735 EXP | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config… | Patch early | 9.1 critical | 50.6% | 2024-03-27 |
| CVE-2005-0553 EXP | Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers… | Patch early | 5.1 medium | 50.6% | 2005-05-02 |
| CVE-2011-3639 EXP | The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not pro… | Patch early | 4.3 medium | 50.6% | 2011-11-30 |
| CVE-2014-9308 EXP | Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin b… | Patch early | 6.5 medium | 50.6% | 2015-01-15 |
| CVE-2001-1410 EXP | Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow… | Patch early | 5.0 medium | 50.5% | 2003-08-18 |
| CVE-2013-1884 EXP | The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault… | Patch early | 5.0 medium | 50.5% | 2013-05-02 |
| CVE-2018-19524 EXP | An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 dev… | Patch early | 9.8 critical | 50.5% | 2019-03-21 |
| CVE-2012-2336 EXP | sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings… | Patch early | 5.0 medium | 50.3% | 2012-05-11 |
| CVE-2014-7285 EXP | The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by… | Patch early | 6.5 medium | 50.3% | 2014-12-17 |
| CVE-2017-16720 EXP | A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the t… | Patch early | 9.8 critical | 50.3% | 2018-01-05 |
| CVE-2017-6465 EXP | Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; howeve… | Patch early | 9.8 critical | 50.3% | 2017-03-10 |
| CVE-2012-3363 EXP | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attac… | Patch early | 9.1 critical | 50.2% | 2013-02-13 |
| CVE-2012-4915 EXP | Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .… | Patch early | 5.0 medium | 50% | 2014-05-29 |
| CVE-2025-58434 EXP | Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint… | Patch early | 9.8 critical | 49.9% | 2025-09-12 |
| CVE-2016-6909 EXP | Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 a… | Patch early | 9.8 critical | 49.9% | 2016-08-24 |
| CVE-2015-2994 EXP | Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by up… | Patch early | 6.5 medium | 49.8% | 2015-06-08 |
| CVE-2007-2447 EXP | The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters invol… | Patch early | 6.0 medium | 49.8% | 2007-05-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt