CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,554 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
149,187 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-0063 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 8.8 high | 39.1% | 2016-02-10 |
| CVE-2013-1309 EXP | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that… | Patch early | 9.3 high | 39.1% | 2013-05-15 |
| CVE-2023-32235 EXP | Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory travers… | Patch early | 7.5 high | 39.1% | 2023-05-05 |
| CVE-2008-1963 EXP | PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 39% | 2008-04-25 |
| CVE-2008-2645 EXP | Multiple PHP remote file inclusion vulnerabilities in Brim (formerly Booby) 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in th… | Patch early | 7.5 high | 39% | 2008-06-10 |
| CVE-2017-0283 EXP | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… | Patch early | 8.8 high | 39% | 2017-06-15 |
| CVE-2008-1472 EXP | Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5… | Patch early | 9.3 high | 39% | 2008-03-24 |
| CVE-2018-12054 EXP | Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal. | Patch early | 7.5 high | 39% | 2018-06-08 |
| CVE-2021-35380 EXP | A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain a… | Patch early | 7.5 high | 39% | 2022-02-15 |
| CVE-2003-1328 EXP | The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to… | Patch early | 7.5 high | 38.9% | 2003-02-19 |
| CVE-2015-0554 EXP | The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly restrict access to the web interfa… | Patch early | 9.4 high | 38.9% | 2015-01-21 |
| CVE-2016-0121 EXP | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gol… | Patch early | 8.8 high | 38.9% | 2016-03-09 |
| CVE-2018-1000094 EXP | CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has… | Patch early | 7.2 high | 38.8% | 2018-03-13 |
| CVE-2003-0161 EXP | The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int ty… | Patch early | 10.0 high | 38.8% | 2003-04-02 |
| CVE-2020-5504 EXP | In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of… | Patch early | 8.8 high | 38.8% | 2020-01-09 |
| CVE-2005-2612 EXP | Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[… | Patch early | 7.5 high | 38.8% | 2005-08-17 |
| CVE-2008-0610 EXP | Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp in vncviewer for UltraVNC 1.0… | Patch early | 9.3 high | 38.8% | 2008-02-06 |
| CVE-2008-0114 EXP | Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to… | Patch early | 9.3 high | 38.8% | 2008-03-11 |
| CVE-2001-0554 EXP | Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of opt… | Patch early | 10.0 high | 38.7% | 2001-08-14 |
| CVE-2008-4449 EXP | Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIVMSG message. | Patch early | 9.3 high | 38.7% | 2008-10-06 |
| CVE-2006-2389 EXP | Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to… | Patch early | 9.3 high | 38.7% | 2006-07-11 |
| CVE-2023-26609 EXP | ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field. | Patch early | 7.2 high | 38.7% | 2023-02-27 |
| CVE-2015-2562 EXP | Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute… | Patch early | 7.5 high | 38.7% | 2015-03-20 |
| CVE-2006-0005 EXP | Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the de… | Patch early | 9.3 high | 38.7% | 2006-02-14 |
| CVE-2003-0209 EXP | Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large s… | Patch early | 10.0 high | 38.6% | 2003-05-05 |
| CVE-2005-0048 EXP | Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service… | Patch early | 7.5 high | 38.6% | 2005-05-02 |
| CVE-2018-7658 EXP | NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service (daemon crash) by sending exa… | Patch early | 7.5 high | 38.5% | 2018-03-26 |
| CVE-2012-0267 EXP | The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter that… | Patch early | 9.3 high | 38.5% | 2012-01-15 |
| CVE-2021-27928 EXP | A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona… | Patch early | 7.2 high | 38.4% | 2021-03-19 |
| CVE-2014-3996 EXP | SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MS… | Patch early | 7.5 high | 38.4% | 2014-12-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt