CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,152 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
149,465 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-4265 EXP | Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to execute arbitrary code via a l… | Patch early | 9.3 high | 31.4% | 2009-12-10 |
| CVE-2012-0708 EXP | Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.… | Patch early | 9.3 high | 31.4% | 2012-04-22 |
| CVE-2009-4962 EXP | Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a .wav file. NOTE: some of thes… | Patch early | 9.3 high | 31.4% | 2010-07-28 |
| CVE-2002-0693 EXP | Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal… | Patch early | 7.5 high | 31.3% | 2002-10-10 |
| CVE-2015-2460 EXP | ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Wind… | Patch early | 9.3 high | 31.3% | 2015-08-15 |
| CVE-2007-3493 EXP | A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other produ… | Patch early | 7.5 high | 31.3% | 2007-06-29 |
| CVE-2010-1465 EXP | Stack-based buffer overflow in Trellian FTP client 3.01, including 3.1.3.1789, allows remote attackers to execute arbitrary code via a long PASV respo… | Patch early | 9.3 high | 31.3% | 2010-04-16 |
| CVE-2006-0143 EXP | Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file conta… | Patch early | 7.5 high | 31.3% | 2006-01-09 |
| CVE-2019-0667 EXP | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code E… | Patch early | 7.5 high | 31.3% | 2019-04-08 |
| CVE-2007-0427 EXP | Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.… | Patch early | 9.3 high | 31.2% | 2007-01-23 |
| CVE-2002-0702 EXP | Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE optio… | Patch early | 10.0 high | 31.1% | 2002-07-26 |
| CVE-2009-2566 EXP | Stack-based buffer overflow in TFM MMPlayer 2.0, and possibly 2.0.0.30, allows remote attackers to execute arbitrary code via a long string in a playl… | Patch early | 9.3 high | 31.1% | 2009-07-21 |
| CVE-2013-4878 EXP | The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directi… | Patch early | 7.5 high | 31.1% | 2013-07-18 |
| CVE-2011-0499 EXP | Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earlier versions, and VideoSpirit Lite 1.4.0.1 and possibly other versions, allows user-assist… | Patch early | 9.3 high | 31% | 2011-01-20 |
| CVE-2021-24146 EXP | Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the expo… | Patch early | 7.5 high | 31% | 2021-03-18 |
| CVE-2008-0311 EXP | Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (STMulticastService) 6.4 in Borla… | Patch early | 9.3 high | 31% | 2008-04-06 |
| CVE-2013-2569 EXP | A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could… | Patch early | 7.5 high | 31% | 2020-01-29 |
| CVE-2014-8387 EXP | cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metachara… | Patch early | 9.0 high | 30.9% | 2014-11-20 |
| CVE-2016-1960 EXP | Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows re… | Patch early | 8.8 high | 30.9% | 2016-03-13 |
| CVE-2009-1641 EXP | Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram… | Patch early | 9.3 high | 30.9% | 2009-05-15 |
| CVE-2010-2553 EXP | The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decompress media files, which allows… | Patch early | 9.3 high | 30.9% | 2010-08-11 |
| CVE-2017-2986 EXP | Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (FLV) codec. Successful exploita… | Patch early | 8.8 high | 30.9% | 2017-02-15 |
| CVE-2008-0470 EXP | A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method. | Patch early | 9.3 high | 30.9% | 2008-01-29 |
| CVE-2010-5081 EXP | Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code via a long URL in a .pls file. | Patch early | 9.3 high | 30.9% | 2011-12-25 |
| CVE-2009-3214 EXP | Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code via a crafted Slideshow proje… | Patch early | 9.3 high | 30.8% | 2009-09-16 |
| CVE-2010-0017 EXP | Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle atta… | Patch early | 9.3 high | 30.8% | 2010-02-10 |
| CVE-2016-0974 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 o… | Patch early | 8.8 high | 30.8% | 2016-02-10 |
| CVE-2015-6168 EXP | Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microso… | Patch early | 9.3 high | 30.7% | 2015-12-09 |
| CVE-2011-0500 EXP | Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions; allows user-assisted remote a… | Patch early | 9.3 high | 30.7% | 2011-01-20 |
| CVE-2009-2650 EXP | Heap-based buffer overflow in Sorcerer Software MultiMedia Jukebox 4.0 Build 020124 allows remote attackers to cause a denial of service (application… | Patch early | 9.3 high | 30.7% | 2009-07-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt