CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,939 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
149,010 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-2595 EXP | Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code via a long id parameter in a… | Patch early | 10.0 high | 59.7% | 2011-09-14 |
| CVE-2008-5159 EXP | Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to… | Patch early | 10.0 high | 59.7% | 2008-11-18 |
| CVE-2017-11870 EXP | ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the curren… | Patch early | 7.5 high | 59.6% | 2017-11-15 |
| CVE-2017-11840 EXP | ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to g… | Patch early | 7.5 high | 59.6% | 2017-11-15 |
| CVE-2017-11841 EXP | ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to g… | Patch early | 7.5 high | 59.6% | 2017-11-15 |
| CVE-2014-8424 EXP | ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication. | Patch early | 7.8 high | 59.6% | 2014-11-28 |
| CVE-2021-33393 EXP | lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivil… | Patch early | 8.8 high | 59.6% | 2021-06-09 |
| CVE-2012-4333 EXP | Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung N… | Patch early | 10.0 high | 59.6% | 2012-08-14 |
| CVE-2005-0768 EXP | Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attacke… | Patch early | 10.0 high | 59.5% | 2005-05-02 |
| CVE-2022-47075 EXP | An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to Expo… | Patch early | 7.5 high | 59.4% | 2023-02-28 |
| CVE-2017-16249 EXP | The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to ha… | Patch early | 7.5 high | 59.4% | 2017-11-10 |
| CVE-2007-1868 EXP | The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP… | Patch early | 10.0 high | 59.3% | 2007-04-04 |
| CVE-2004-1595 EXP | Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field. | Patch early | 7.5 high | 59.3% | 2004-10-13 |
| CVE-2012-2957 EXP | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file incl… | Patch early | 7.2 high | 59.3% | 2012-07-23 |
| CVE-2012-0500 EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaF… | Patch early | 10.0 high | 59.2% | 2012-02-15 |
| CVE-2007-4370 EXP | Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbitrary code via a long string to… | Patch early | 7.5 high | 59.2% | 2007-08-15 |
| CVE-2007-3216 EXP | Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.1 allow remote… | Patch early | 10.0 high | 59.2% | 2007-06-14 |
| CVE-2008-4037 EXP | Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers t… | Patch early | 9.3 high | 59.1% | 2008-11-12 |
| CVE-2017-1000170 EXP | jqueryFileTree 2.1.5 and older Directory Traversal | Patch early | 7.5 high | 59.1% | 2017-11-17 |
| CVE-2012-0549 EXP | Unspecified vulnerability in the Oracle AutoVue Office component in Oracle Supply Chain Products Suite 20.1.1 allows remote attackers to affect confid… | Patch early | 7.5 high | 59% | 2012-05-03 |
| CVE-2014-10021 EXP | Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 59% | 2015-01-13 |
| CVE-2006-6063 EXP | Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (… | Patch early | 7.5 high | 59% | 2006-11-22 |
| CVE-2021-42840 EXP | SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account t… | Patch early | 8.8 high | 58.9% | 2021-10-22 |
| CVE-2021-46381 EXP | Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow]. | Patch early | 7.5 high | 58.9% | 2022-03-04 |
| CVE-2011-1996 EXP | Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessi… | Patch early | 9.3 high | 58.8% | 2011-10-12 |
| CVE-2003-0605 EXP | The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to… | Patch early | 7.5 high | 58.8% | 2003-08-27 |
| CVE-2018-0707 EXP | Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to… | Patch early | 7.2 high | 58.8% | 2018-07-17 |
| CVE-2006-1364 EXP | Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allo… | Patch early | 7.5 high | 58.7% | 2006-03-23 |
| CVE-2012-0432 EXP | Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified… | Patch early | 10.0 high | 58.7% | 2012-12-25 |
| CVE-2007-1373 EXP | Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via… | Patch early | 10.0 high | 58.7% | 2007-03-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt