CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,646 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
318,578 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-4075 EXP | The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby para… | Patch early | 7.5 high | 51.9% | 2011-11-02 |
| CVE-2013-6129 EXP | The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password]… | Patch early | 7.5 high | 51.9% | 2013-10-19 |
| CVE-1999-0046 EXP | Buffer overflow of rlogin program using TERM environmental variable. | Patch early | 10.0 high | 51.9% | 1997-02-06 |
| CVE-2015-4632 EXP | Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 all… | Patch early | 7.5 high | 51.8% | 2018-10-18 |
| CVE-2005-1018 EXP | Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of s… | Patch early | 7.5 high | 51.8% | 2005-05-02 |
| CVE-2016-3288 EXP | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vuln… | Patch early | 7.5 high | 51.8% | 2016-08-09 |
| CVE-2018-0946 EXP | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine M… | Patch early | 7.5 high | 51.8% | 2018-05-09 |
| CVE-2002-2268 EXP | Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL. | Patch early | 9.4 high | 51.7% | 2002-12-31 |
| CVE-2010-0557 EXP | IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging har… | Patch early | 7.5 high | 51.7% | 2010-02-05 |
| CVE-2007-4232 EXP | PHP remote file inclusion vulnerability in admin/inc/change_action.php in Andreas Robertz PHPNews 0.93 allows remote attackers to execute arbitrary PH… | Patch early | 6.8 medium | 51.7% | 2007-08-08 |
| CVE-2022-28171 EXP | The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validati… | Patch early | 7.5 high | 51.6% | 2022-06-27 |
| CVE-2009-0714 EXP | Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before bu… | Patch early | 7.2 high | 51.6% | 2009-05-14 |
| CVE-2009-1534 EXP | Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3,… | Patch early | 9.3 high | 51.6% | 2009-08-12 |
| CVE-2017-8731 EXP | Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, d… | Patch early | 7.5 high | 51.6% | 2017-09-13 |
| CVE-2011-0522 EXP | The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/codec/subtitles/subsusf.c) in Vide… | Patch early | 6.8 medium | 51.5% | 2011-02-07 |
| CVE-2017-8496 EXP | Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user when Microso… | Patch early | 7.5 high | 51.5% | 2017-06-15 |
| CVE-2013-1847 EXP | The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of ser… | Patch early | 5.0 medium | 51.4% | 2013-05-02 |
| CVE-2018-1418 EXP | IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824. | Patch early | 8.8 high | 51.4% | 2018-04-26 |
| CVE-2017-13772 EXP | Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary cod… | Patch early | 8.8 high | 51.4% | 2017-10-23 |
| CVE-2013-0753 EXP | Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox before 18.0, Firefox ESR 10.x b… | Patch early | 9.3 high | 51.3% | 2013-01-13 |
| CVE-2010-4052 EXP | Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, all… | Patch early | 5.0 medium | 51.3% | 2011-01-13 |
| CVE-2022-0557 EXP | OS Command Injection in Packagist microweber/microweber prior to 1.2.11. | Patch early | 7.2 high | 51.2% | 2022-02-11 |
| CVE-2005-2733 EXP | upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to e… | Patch early | 7.5 high | 51.2% | 2005-08-30 |
| CVE-2016-0956 EXP | The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sens… | Patch early | 7.5 high | 51.2% | 2016-02-10 |
| CVE-2002-0013 EXP | Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain p… | Patch early | 10.0 high | 51.1% | 2002-02-13 |
| CVE-2008-1365 EXP | Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, al… | Patch early | 6.4 medium | 51.1% | 2008-03-17 |
| CVE-2017-1000083 EXP | backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via… | Patch early | 7.8 high | 51.1% | 2017-09-05 |
| CVE-2010-0033 EXP | Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint documen… | Patch early | 9.3 high | 51.1% | 2010-02-10 |
| CVE-2016-0199 EXP | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch early | 8.8 high | 51% | 2016-06-16 |
| CVE-2000-0665 EXP | GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username. | Patch early | 5.0 medium | 51% | 2000-07-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt