CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,939 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
205,689 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-2731 EXP | Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enabled… | Patch early | 6.8 medium | 31.1% | 2010-09-15 |
| CVE-2005-4131 EXP | Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to… | Patch early | 6.8 medium | 31.1% | 2005-12-09 |
| CVE-2004-1546 EXP | Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or… | Patch early | 5.0 medium | 31.1% | 2004-12-31 |
| CVE-2015-7855 EXP | The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion… | Patch early | 6.5 medium | 31.1% | 2017-08-07 |
| CVE-2007-4891 EXP | A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3)… | Patch early | 6.8 medium | 31% | 2007-09-14 |
| CVE-2009-2255 EXP | Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to exec… | Patch early | 6.8 medium | 31% | 2009-06-30 |
| CVE-2007-4466 EXP | Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code… | Patch early | 6.8 medium | 30.9% | 2007-10-09 |
| CVE-2017-3078 EXP | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Succe… | Patch early | 9.8 critical | 30.9% | 2017-06-20 |
| CVE-2011-2755 EXP | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 30.9% | 2011-07-17 |
| CVE-2006-6665 EXP | Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute arbitrary code via a long file… | Patch early | 6.8 medium | 30.9% | 2006-12-20 |
| CVE-2003-1172 EXP | Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access ar… | Patch early | 5.0 medium | 30.8% | 2003-12-31 |
| CVE-2004-1602 EXP | ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to ident… | Patch early | 5.0 medium | 30.7% | 2004-10-15 |
| CVE-2002-2006 EXP | The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sens… | Patch early | 5.0 medium | 30.7% | 2002-12-31 |
| CVE-2024-55963 EXP | An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causi… | Patch early | 6.5 medium | 30.7% | 2025-03-26 |
| CVE-2011-3976 EXP | Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST c… | Patch early | 6.8 medium | 30.6% | 2011-10-04 |
| CVE-2018-7300 EXP | Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows… | Patch early | 9.8 critical | 30.6% | 2018-02-22 |
| CVE-1999-1375 EXP | FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file… | Patch early | 5.0 medium | 30.5% | 1999-02-11 |
| CVE-2016-2385 EXP | Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows re… | Patch early | 9.8 critical | 30.5% | 2016-04-11 |
| CVE-2021-25158 EXP | A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.… | Patch early | 5.9 medium | 30.5% | 2021-03-30 |
| CVE-2011-0419 EXP | Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apach… | Patch early | 4.3 medium | 30.4% | 2011-05-16 |
| CVE-2016-7182 EXP | The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2… | Patch early | 9.8 critical | 30.3% | 2016-10-14 |
| CVE-2007-3872 EXP | Multiple stack-based buffer overflows in the Shared Trace Service (OVTrace) service for HP OpenView Operations A.07.50 for Windows, and possibly earli… | Patch early | 6.8 medium | 30.3% | 2007-08-09 |
| CVE-2018-10718 EXP | Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary c… | Patch early | 10.0 critical | 30.2% | 2018-05-03 |
| CVE-2025-50154 EXP | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network… | Patch early | 6.5 medium | 30.2% | 2025-08-12 |
| CVE-2015-4870 EXP | Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability… | Patch early | 4.0 medium | 30.1% | 2015-10-21 |
| CVE-2008-4295 EXP | Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection t… | Patch early | 5.4 medium | 30.1% | 2008-09-27 |
| CVE-2006-3014 EXP | Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an… | Patch early | 5.1 medium | 30.1% | 2006-06-22 |
| CVE-2017-1129 EXP | IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to ha… | Patch early | 6.5 medium | 30.1% | 2017-09-05 |
| CVE-2024-22836 EXP | An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to… | Patch early | 9.8 critical | 30% | 2024-02-08 |
| CVE-2007-5217 EXP | Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) Kazaa 3.2.7 and (2) Grokster, a… | Patch early | 6.8 medium | 30% | 2007-10-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt