CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,646 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
149,203 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-4388 EXP | The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate down… | Patch early | 9.3 high | 37.7% | 2009-01-20 |
| CVE-2016-1101 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.7% | 2016-05-11 |
| CVE-2016-1103 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.7% | 2016-05-11 |
| CVE-2016-1105 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.7% | 2016-05-11 |
| CVE-2016-4108 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.7% | 2016-05-11 |
| CVE-2008-4385 EXP | Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the download and execution of arbitrary… | Patch early | 9.3 high | 37.7% | 2008-10-14 |
| CVE-2015-1328 EXP | The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions f… | Patch early | 7.8 high | 37.7% | 2016-11-28 |
| CVE-2003-0838 EXP | Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and insertin… | Patch early | 7.5 high | 37.6% | 2003-11-17 |
| CVE-2006-4924 EXP | sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH p… | Patch early | 7.8 high | 37.5% | 2006-09-27 |
| CVE-2020-14008 EXP | Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which le… | Patch early | 7.2 high | 37.5% | 2020-09-04 |
| CVE-2009-1569 EXP | Multiple stack-based buffer overflows in Novell iPrint Client 4.38, 5.30, and possibly other versions before 5.32 allow remote attackers to execute ar… | Patch early | 9.3 high | 37.5% | 2009-12-08 |
| CVE-2007-5244 EXP | Stack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versions on Solaris, allows remote a… | Patch early | 9.3 high | 37.5% | 2007-10-06 |
| CVE-2019-15978 EXP | Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker… | Patch early | 7.2 high | 37.5% | 2020-01-06 |
| CVE-2012-0198 EXP | Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Softwa… | Patch early | 9.3 high | 37.4% | 2012-03-06 |
| CVE-2009-1547 EXP | Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted dat… | Patch early | 8.8 high | 37.4% | 2009-10-14 |
| CVE-2016-10009 EXP | Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modul… | Patch early | 7.3 high | 37.4% | 2017-01-05 |
| CVE-2015-2455 EXP | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Go… | Patch early | 9.3 high | 37.4% | 2015-08-15 |
| CVE-2014-1764 EXP | Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism by leveraging "ob… | Patch early | 10.0 high | 37.4% | 2014-04-27 |
| CVE-2010-3106 EXP | The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the debug parameter, which allows… | Patch early | 9.3 high | 37.3% | 2010-08-23 |
| CVE-2013-3928 EXP | Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary cod… | Patch early | 9.3 high | 37.3% | 2014-03-11 |
| CVE-2000-0854 EXP | When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, whic… | Patch early | 10.0 high | 37.2% | 2000-11-14 |
| CVE-2016-1106 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 7.5 high | 37.2% | 2016-05-11 |
| CVE-2006-6723 EXP | The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large… | Patch early | 7.8 high | 37.2% | 2006-12-26 |
| CVE-2009-0476 EXP | Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio components for .N… | Patch early | 9.3 high | 37% | 2009-02-08 |
| CVE-2005-0582 EXP | Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code via a long filename in a PUTOLF… | Patch early | 10.0 high | 37% | 2005-05-02 |
| CVE-2011-5165 EXP | Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to execute arbit… | Patch early | 9.3 high | 37% | 2012-09-15 |
| CVE-2018-11529 EXP | VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV fi… | Patch early | 8.0 high | 37% | 2018-07-11 |
| CVE-2015-4624 EXP | Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens. | Patch early | 7.5 high | 37% | 2017-03-31 |
| CVE-2017-6019 EXP | An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests t… | Patch early | 7.5 high | 36.9% | 2017-04-07 |
| CVE-2012-5961 EXP | Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka lib… | Patch early | 10.0 high | 36.9% | 2013-01-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt