CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,105 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
149,034 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2001-0538 EXP | Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTM… | Patch early | 10.0 high | 52.9% | 2001-08-14 |
| CVE-2014-1903 EXP | admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not… | Patch early | 7.5 high | 52.8% | 2014-02-18 |
| CVE-2007-4921 EXP | PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP cod… | Patch early | 7.5 high | 52.8% | 2007-09-17 |
| CVE-2000-0457 EXP | ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) a… | Patch early | 7.5 high | 52.8% | 2000-05-11 |
| CVE-2012-5691 EXP | Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via… | Patch early | 9.3 high | 52.7% | 2012-12-19 |
| CVE-2008-0108 EXP | Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005,… | Patch early | 9.3 high | 52.6% | 2008-02-12 |
| CVE-2003-1041 EXP | Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing "… | Patch early | 7.5 high | 52.6% | 2004-06-14 |
| CVE-2009-3958 EXP | Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adob… | Patch early | 10.0 high | 52.6% | 2010-01-13 |
| CVE-2014-5468 EXP | A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG f… | Patch early | 8.8 high | 52.6% | 2020-02-07 |
| CVE-2017-8734 EXP | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of… | Patch early | 7.5 high | 52.5% | 2017-09-13 |
| CVE-2016-0710 EXP | Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL com… | Patch early | 8.8 high | 52.4% | 2016-04-11 |
| CVE-2022-35919 EXP | MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized fo… | Patch early | 7.4 high | 52.3% | 2022-08-01 |
| CVE-2007-4620 EXP | Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used… | Patch early | 9.0 high | 52.3% | 2008-04-07 |
| CVE-2019-11447 EXP | An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the… | Patch early | 8.8 high | 52.3% | 2019-04-22 |
| CVE-2015-0925 EXP | The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Un… | Patch early | 9.0 high | 52.2% | 2015-01-22 |
| CVE-2008-3013 EXP | gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP… | Patch early | 9.3 high | 52.1% | 2008-09-11 |
| CVE-2010-3585 EXP | Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and ava… | Patch early | 9.0 high | 52.1% | 2010-10-14 |
| CVE-2008-1898 EXP | A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers… | Patch early | 9.3 high | 52% | 2008-04-21 |
| CVE-2012-3951 EXP | The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutin… | Patch early | 7.5 high | 52% | 2012-07-31 |
| CVE-2011-4453 EXP | The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a… | Patch early | 7.5 high | 52% | 2011-12-22 |
| CVE-2006-6133 EXP | Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and… | Patch early | 7.6 high | 52% | 2006-11-28 |
| CVE-2007-3034 EXP | Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows rem… | Patch early | 9.3 high | 51.9% | 2007-08-14 |
| CVE-2013-4812 EXP | UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (I… | Patch early | 10.0 high | 51.9% | 2013-09-16 |
| CVE-2011-4075 EXP | The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby para… | Patch early | 7.5 high | 51.9% | 2011-11-02 |
| CVE-2013-6129 EXP | The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password]… | Patch early | 7.5 high | 51.9% | 2013-10-19 |
| CVE-1999-0046 EXP | Buffer overflow of rlogin program using TERM environmental variable. | Patch early | 10.0 high | 51.9% | 1997-02-06 |
| CVE-2015-4632 EXP | Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 all… | Patch early | 7.5 high | 51.8% | 2018-10-18 |
| CVE-2005-1018 EXP | Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of s… | Patch early | 7.5 high | 51.8% | 2005-05-02 |
| CVE-2016-3288 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vuln… | Patch early | 7.5 high | 51.8% | 2016-08-09 |
| CVE-2018-0946 EXP | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine M… | Patch early | 7.5 high | 51.8% | 2018-05-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt