CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,534 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
205,906 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-3266 EXP | Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite 1.2 and earlier, when register_globals is enabled, allow remote attackers to execu… | Patch early | 5.1 medium | 18% | 2006-06-27 |
| CVE-2004-0633 EXP | The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow. | Patch early | 5.0 medium | 18% | 2004-12-06 |
| CVE-2019-8041 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 17.9% | 2019-08-20 |
| CVE-2019-8046 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 17.9% | 2019-08-20 |
| CVE-2021-40651 EXP | OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary fil… | Patch early | 6.5 medium | 17.9% | 2021-09-29 |
| CVE-2010-2091 EXP | Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a… | Patch early | 4.3 medium | 17.9% | 2010-05-27 |
| CVE-2006-5646 EXP | Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.1… | Patch early | 5.0 medium | 17.9% | 2006-11-01 |
| CVE-2018-11741 EXP | NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOT… | Patch early | 9.8 critical | 17.9% | 2018-12-26 |
| CVE-2006-5645 EXP | Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of a… | Patch early | 5.0 medium | 17.9% | 2006-11-01 |
| CVE-2017-0062 EXP | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 201… | Patch early | 4.7 medium | 17.8% | 2017-03-17 |
| CVE-2004-0637 EXP | Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which… | Patch early | 6.5 medium | 17.8% | 2004-09-02 |
| CVE-2016-4204 EXP | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 17.8% | 2016-07-13 |
| CVE-2016-4205 EXP | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 17.8% | 2016-07-13 |
| CVE-2016-4206 EXP | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 17.8% | 2016-07-13 |
| CVE-2016-4207 EXP | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 17.8% | 2016-07-13 |
| CVE-2016-4208 EXP | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 17.8% | 2016-07-13 |
| CVE-2021-31159 EXP | Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Pas… | Patch early | 5.3 medium | 17.8% | 2021-06-16 |
| CVE-2005-3634 EXP | frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to ar… | Patch early | 5.0 medium | 17.8% | 2005-11-16 |
| CVE-1999-0877 EXP | Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME. | Patch early | 4.3 medium | 17.7% | 1999-10-01 |
| CVE-2001-1489 EXP | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large numbe… | Patch early | 5.0 medium | 17.7% | 2001-12-31 |
| CVE-2007-0463 EXP | Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash)… | Patch early | 5.0 medium | 17.7% | 2007-01-29 |
| CVE-2006-1010 EXP | Buffer overflow in socket/request.c in CrossFire before 1.9.0, when oldsocketmode is enabled, allows remote attackers to cause a denial of service (se… | Patch early | 6.4 medium | 17.6% | 2006-03-06 |
| CVE-2021-24274 EXP | The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribu… | Patch early | 6.1 medium | 17.6% | 2021-05-05 |
| CVE-2002-1705 EXP | Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{… | Patch early | 5.0 medium | 17.6% | 2002-12-31 |
| CVE-2015-2279 EXP | cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows remote attackers to execute a… | Patch early | 9.8 critical | 17.6% | 2017-07-25 |
| CVE-2019-9083 EXP | SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued. | Patch early | 9.8 critical | 17.6% | 2019-03-21 |
| CVE-2000-0347 EXP | Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name. | Patch early | 5.0 medium | 17.6% | 2000-05-02 |
| CVE-2006-6659 EXP | The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Ex… | Patch early | 5.0 medium | 17.6% | 2006-12-20 |
| CVE-2001-0150 EXP | Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote a… | Patch early | 5.1 medium | 17.6% | 2001-06-02 |
| CVE-2008-4493 EXP | Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to… | Patch early | 6.8 medium | 17.6% | 2008-10-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt