CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,049 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
206,146 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0655 EXP | Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing… | Patch early | 5.0 medium | 12.7% | 2000-07-25 |
| CVE-2006-0747 EXP | Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue value… | Patch early | 5.0 medium | 12.7% | 2006-05-23 |
| CVE-2017-14097 EXP | An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to decrypt… | Patch early | 9.8 critical | 12.7% | 2018-01-19 |
| CVE-2006-2426 EXP | Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial… | Patch early | 6.4 medium | 12.7% | 2006-05-17 |
| CVE-2009-2957 EXP | Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to… | Patch early | 6.8 medium | 12.7% | 2009-09-02 |
| CVE-2014-9611 EXP | Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/in… | Patch early | 9.8 critical | 12.7% | 2017-09-19 |
| CVE-2019-0948 EXP | An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when it improperly parses XML input containing a reference t… | Patch early | 4.7 medium | 12.7% | 2019-06-12 |
| CVE-2011-4107 EXP | The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 a… | Patch early | 6.5 medium | 12.7% | 2011-11-17 |
| CVE-2010-2094 EXP | Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information… | Patch early | 6.8 medium | 12.7% | 2010-05-27 |
| CVE-2009-0696 EXP | The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a… | Patch early | 4.3 medium | 12.6% | 2009-07-29 |
| CVE-2008-5692 EXP | Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via… | Patch early | 5.0 medium | 12.6% | 2008-12-19 |
| CVE-2017-1002002 EXP | Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/ | Patch early | 9.8 critical | 12.6% | 2017-09-14 |
| CVE-2017-14459 EXP | An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a… | Patch early | 10.0 critical | 12.6% | 2018-04-11 |
| CVE-2009-1490 EXP | Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrar… | Patch early | 5.0 medium | 12.6% | 2009-05-05 |
| CVE-2012-4513 EXP | khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via la… | Patch early | 6.4 medium | 12.6% | 2012-11-11 |
| CVE-2005-4134 EXP | Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and dela… | Patch early | 5.0 medium | 12.6% | 2005-12-09 |
| CVE-2017-5415 EXP | An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and furthe… | Patch early | 5.3 medium | 12.6% | 2018-06-11 |
| CVE-2018-11509 EXP | ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from t… | Patch early | 9.8 critical | 12.6% | 2018-08-16 |
| CVE-2021-25159 EXP | A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x… | Patch early | 6.5 medium | 12.6% | 2021-03-30 |
| CVE-2004-1491 EXP | Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or lau… | Patch early | 5.0 medium | 12.6% | 2004-12-31 |
| CVE-2018-19861 EXP | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is… | Patch early | 9.8 critical | 12.6% | 2019-01-03 |
| CVE-2018-19862 EXP | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is… | Patch early | 9.8 critical | 12.6% | 2019-01-03 |
| CVE-2018-8898 EXP | A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer=… | Patch early | 9.8 critical | 12.5% | 2018-05-23 |
| CVE-2012-5672 EXP | Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read a… | Patch early | 4.3 medium | 12.5% | 2012-10-25 |
| CVE-2015-5354 EXP | Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks v… | Patch early | 5.8 medium | 12.5% | 2015-07-01 |
| CVE-2012-4528 EXP | The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP app… | Patch early | 5.0 medium | 12.5% | 2012-12-28 |
| CVE-2017-17976 EXP | In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. | Patch early | 9.8 critical | 12.5% | 2018-01-26 |
| CVE-2006-0306 EXP | The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Back… | Patch early | 5.0 medium | 12.5% | 2006-01-19 |
| CVE-2018-10824 EXP | An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-… | Patch early | 9.8 critical | 12.5% | 2018-10-17 |
| CVE-2016-7567 EXP | Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a craf… | Patch early | 9.8 critical | 12.5% | 2017-01-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt