CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,354 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
149,094 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-0015 EXP | DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,… | Patch early | 7.8 high | 49.4% | 2016-01-13 |
| CVE-2008-4114 EXP | srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remot… | Patch early | 7.1 high | 49.3% | 2008-09-16 |
| CVE-2020-6010 EXP | LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection | Patch early | 8.8 high | 49.2% | 2020-04-30 |
| CVE-2004-0200 EXP | Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers… | Patch early | 9.3 high | 49% | 2004-09-28 |
| CVE-2016-0736 EXP | In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CB… | Patch early | 7.5 high | 49% | 2017-07-27 |
| CVE-2012-1803 EXP | RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, whi… | Patch early | 8.5 high | 49% | 2012-04-28 |
| CVE-2007-4776 EXP | Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a Vis… | Patch early | 9.3 high | 49% | 2007-09-10 |
| CVE-2009-0517 EXP | Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields paramet… | Patch early | 10.0 high | 48.9% | 2009-02-11 |
| CVE-2007-2223 EXP | Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode o… | Patch early | 9.3 high | 48.7% | 2007-08-14 |
| CVE-2022-31188 EXP | CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-si… | Patch early | 8.6 high | 48.6% | 2022-08-01 |
| CVE-2003-1339 EXP | Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare allows remote attackers to cau… | Patch early | 10.0 high | 48.6% | 2003-12-31 |
| CVE-2008-1043 EXP | PHP remote file inclusion vulnerability in templates/default/header.inc.php in Linux Web Shop (LWS) php User Base 1.3 BETA allows remote attackers to… | Patch early | 7.5 high | 48.6% | 2008-02-27 |
| CVE-2016-0170 EXP | GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, a… | Patch early | 8.8 high | 48.6% | 2016-05-11 |
| CVE-2003-0725 EXP | Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 an… | Patch early | 7.5 high | 48.6% | 2003-10-20 |
| CVE-2017-11855 EXP | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows… | Patch early | 7.5 high | 48.6% | 2017-11-15 |
| CVE-2009-0182 EXP | Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as… | Patch early | 8.8 high | 48.4% | 2009-01-20 |
| CVE-2003-0816 EXP | Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL co… | Patch early | 7.5 high | 48.4% | 2004-02-03 |
| CVE-2008-1059 EXP | PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers t… | Patch early | 7.5 high | 48.3% | 2008-02-28 |
| CVE-2010-0028 EXP | Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a c… | Patch early | 9.3 high | 48.3% | 2010-02-10 |
| CVE-2013-2827 EXP | An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers… | Patch early | 7.5 high | 48.3% | 2014-01-15 |
| CVE-2018-0706 EXP | Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access sensitive in… | Patch early | 8.8 high | 48.3% | 2018-07-17 |
| CVE-2008-0116 EXP | Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to… | Patch early | 9.3 high | 48.2% | 2008-03-11 |
| CVE-2010-0270 EXP | The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote S… | Patch early | 10.0 high | 48.2% | 2010-04-14 |
| CVE-2016-7189 EXP | The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Remote… | Patch early | 7.5 high | 48.1% | 2016-10-14 |
| CVE-2017-8541 EXP | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… | Patch early | 7.8 high | 48.1% | 2017-05-26 |
| CVE-2012-2110 EXP | The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly inte… | Patch early | 7.5 high | 47.9% | 2012-04-19 |
| CVE-2013-0232 EXP | includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metachar… | Patch early | 7.5 high | 47.9% | 2013-03-20 |
| CVE-2010-4701 EXP | Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows… | Patch early | 7.6 high | 47.8% | 2011-01-20 |
| CVE-2012-4361 EXP | lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via sh… | Patch early | 7.7 high | 47.8% | 2012-08-20 |
| CVE-2014-9566 EXP | Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as u… | Patch early | 7.5 high | 47.7% | 2015-03-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt