CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,483 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
185,350 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-3459 KEV EXP | Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbit… | Patch first | 8.8 high | 86.6% | 2009-10-13 |
| CVE-2015-2426 KEV EXP | Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7… | Patch first | 8.8 high | 86.6% | 2015-07-20 |
| CVE-2019-4716 KEV EXP | IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and the… | Patch first | 9.8 critical | 86.4% | 2019-12-18 |
| CVE-2018-6961 KEV EXP | VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is… | Patch first | 8.1 high | 86.3% | 2018-06-11 |
| CVE-2015-0311 KEV EXP | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.20… | Patch first | 9.8 critical | 85.6% | 2015-01-23 |
| CVE-2025-57819 KEV EXP | FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-sup… | Patch first | 9.8 critical | 85.5% | 2025-08-28 |
| CVE-2014-0322 KEV EXP | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted J… | Patch first | 8.8 high | 85.1% | 2014-02-14 |
| CVE-2013-3906 KEV EXP | GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010… | Patch first | 7.8 high | 84.9% | 2013-11-06 |
| CVE-2018-17463 KEV EXP | Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via… | Patch first | 8.8 high | 84.6% | 2018-11-14 |
| CVE-2020-5722 KEV EXP | The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker ca… | Patch first | 9.8 critical | 84.4% | 2020-03-23 |
| CVE-2017-11317 KEV EXP | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remo… | Patch first | 9.8 critical | 84.2% | 2017-08-23 |
| CVE-2017-0213 KEV EXP | Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows… | Patch first | 7.3 high | 84.1% | 2017-05-12 |
| CVE-2009-3129 KEV EXP | Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Vi… | Patch first | 7.8 high | 84% | 2009-11-11 |
| CVE-2020-3161 KEV EXP | A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a… | Patch first | 9.8 critical | 83.9% | 2020-04-15 |
| CVE-2016-5195 KEV EXP | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of… | Patch first | 7.0 high | 83.5% | 2016-11-10 |
| CVE-2012-1889 KEV EXP | Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or… | Patch first | 8.8 high | 83.5% | 2012-06-13 |
| CVE-2010-1871 KEV EXP | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expr… | Patch first | 8.8 high | 83.4% | 2010-08-05 |
| CVE-2016-10174 KEV EXP | The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffe… | Patch first | 9.8 critical | 83.3% | 2017-01-30 |
| CVE-2009-3953 KEV EXP | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attacker… | Patch first | 8.8 high | 83.2% | 2010-01-13 |
| CVE-2010-3765 KEV EXP | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10… | Patch first | 9.8 critical | 83.2% | 2010-10-28 |
| CVE-2015-1187 KEV EXP | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp. | Patch first | 9.8 critical | 82.9% | 2017-09-21 |
| CVE-2016-7200 KEV EXP | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corrup… | Patch first | 8.8 high | 82.8% | 2016-11-10 |
| CVE-2025-33073 KEV EXP | Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | Patch first | 8.8 high | 82.7% | 2025-06-10 |
| CVE-2010-1297 KEV EXP | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x b… | Patch first | 7.8 high | 82.2% | 2010-06-08 |
| CVE-2010-0806 KEV EXP | Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to… | Patch first | 8.8 high | 82.2% | 2010-03-10 |
| CVE-2018-6789 KEV EXP | An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may ha… | Patch first | 9.8 critical | 82.1% | 2018-02-08 |
| CVE-2009-4324 KEV EXP | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Win… | Patch first | 7.8 high | 81.9% | 2009-12-15 |
| CVE-2018-13382 KEV EXP | An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1… | Patch first | 9.1 critical | 81.7% | 2019-06-04 |
| CVE-2014-4114 KEV EXP | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows R… | Patch first | 7.8 high | 81.6% | 2014-10-15 |
| CVE-2019-0752 KEV EXP | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin… | Patch first | 7.5 high | 81.6% | 2019-04-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt