CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,986 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
185,992 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-6425 EXP | Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code… | Patch early | 9.0 high | 58.2% | 2006-12-27 |
| CVE-2008-0926 EXP | The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which a… | Patch early | 7.5 high | 58.2% | 2008-03-28 |
| CVE-2009-2485 EXP | Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a .ht3 file. | Patch early | 9.3 high | 58.1% | 2009-07-16 |
| CVE-2019-14931 EXP | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote… | Patch early | 9.8 critical | 58.1% | 2019-10-28 |
| CVE-2008-0437 EXP | Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation proces… | Patch early | 10.0 high | 58.1% | 2008-01-23 |
| CVE-2017-8618 EXP | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold,… | Patch early | 7.5 high | 58.1% | 2017-07-11 |
| CVE-2010-1318 EXP | Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11… | Patch early | 10.0 high | 58.1% | 2010-04-20 |
| CVE-2012-0500 EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaF… | Patch early | 10.0 high | 58% | 2012-02-15 |
| CVE-2012-4177 EXP | The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line ar… | Patch early | 10.0 high | 58% | 2012-08-07 |
| CVE-2007-4712 EXP | PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code via a URL in the page paramete… | Patch early | 7.5 high | 57.9% | 2007-09-05 |
| CVE-2005-0554 EXP | Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and… | Patch early | 7.5 high | 57.9% | 2005-05-02 |
| CVE-2008-0081 EXP | Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to… | Patch early | 9.8 critical | 57.9% | 2008-01-16 |
| CVE-2016-7194 EXP | The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via… | Patch early | 7.5 high | 57.9% | 2016-10-14 |
| CVE-2018-7314 EXP | SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. | Patch early | 9.8 critical | 57.8% | 2018-02-22 |
| CVE-2018-6605 EXP | SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHov… | Patch early | 9.8 critical | 57.7% | 2018-02-05 |
| CVE-2014-2850 EXP | The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary command… | Patch early | 8.5 high | 57.7% | 2014-04-11 |
| CVE-2015-1503 EXP | Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot)… | Patch early | 7.5 high | 57.6% | 2018-05-08 |
| CVE-2006-1188 EXP | Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads… | Patch early | 7.5 high | 57.6% | 2006-04-11 |
| CVE-2008-4654 EXP | Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows re… | Patch early | 9.3 high | 57.5% | 2008-10-22 |
| CVE-2006-5854 EXP | Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitr… | Patch early | 7.5 high | 57.5% | 2006-12-03 |
| CVE-2016-8582 EXP | A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve da… | Patch early | 9.8 critical | 57.4% | 2016-10-28 |
| CVE-2017-6526 EXP | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected admi… | Patch early | 9.8 critical | 57.4% | 2017-03-09 |
| CVE-2004-0209 EXP | Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attacker… | Patch early | 10.0 high | 57.4% | 2004-11-03 |
| CVE-2017-0089 EXP | Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via… | Patch early | 8.8 high | 57.3% | 2017-03-17 |
| CVE-2020-15922 EXP | There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) pr… | Patch early | 9.8 critical | 57.3% | 2020-07-24 |
| CVE-2006-3440 EXP | Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary cod… | Patch early | 10.0 high | 57.3% | 2006-08-09 |
| CVE-2016-0100 EXP | Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges via a crafted application, aka… | Patch early | 8.4 high | 57.2% | 2016-03-09 |
| CVE-2019-5029 EXP | An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands s… | Patch early | 9.8 critical | 57.2% | 2019-11-13 |
| CVE-2008-0532 EXP | Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for… | Patch early | 10.0 high | 57.1% | 2008-03-14 |
| CVE-2013-3632 EXP | The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands… | Patch early | 8.8 high | 57.1% | 2014-09-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt