CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,152 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
206,203 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-7257 EXP | CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1… | Patch early | 4.3 medium | 11.6% | 2010-06-29 |
| CVE-2016-9683 EXP | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative i… | Patch early | 9.8 critical | 11.6% | 2017-02-22 |
| CVE-2007-4254 EXP | Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Designer 7.0 for Microsoft Visual St… | Patch early | 6.8 medium | 11.5% | 2007-08-08 |
| CVE-2008-0944 EXP | Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via… | Patch early | 5.0 medium | 11.5% | 2008-02-25 |
| CVE-2018-5724 EXP | MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi. | Patch early | 9.8 critical | 11.5% | 2018-01-16 |
| CVE-2019-10709 EXP | AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potenti… | Patch early | 9.8 critical | 11.5% | 2019-09-04 |
| CVE-2019-6273 EXP | download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files. | Patch early | 6.5 medium | 11.5% | 2019-03-21 |
| CVE-2010-0397 EXP | The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, w… | Patch early | 5.0 medium | 11.5% | 2010-03-16 |
| CVE-2018-15120 EXP | libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application cras… | Patch early | 6.5 medium | 11.5% | 2018-08-24 |
| CVE-2008-6222 EXP | Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows remote attackers to read arbi… | Patch early | 5.0 medium | 11.5% | 2009-02-20 |
| CVE-2016-0070 EXP | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT… | Patch early | 5.5 medium | 11.5% | 2016-10-14 |
| CVE-2017-2523 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | Patch early | 9.8 critical | 11.5% | 2017-05-22 |
| CVE-2007-1912 EXP | Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file. | Patch early | 6.8 medium | 11.5% | 2007-04-10 |
| CVE-2014-9148 EXP | Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administr… | Patch early | 9.8 critical | 11.4% | 2017-10-16 |
| CVE-2022-22831 EXP | An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header. | Patch early | 9.8 critical | 11.4% | 2022-02-06 |
| CVE-2010-3682 EXP | Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXP… | Patch early | 4.0 medium | 11.4% | 2011-01-11 |
| CVE-2015-3221 EXP | OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated use… | Patch early | 4.0 medium | 11.4% | 2015-08-26 |
| CVE-2013-4788 EXP | The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the ra… | Patch early | 5.1 medium | 11.4% | 2013-10-04 |
| CVE-2007-0107 EXP | WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers… | Patch early | 6.8 medium | 11.4% | 2007-01-09 |
| CVE-2024-40422 EXP | The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker ca… | Patch early | 9.1 critical | 11.4% | 2024-07-24 |
| CVE-2010-1056 EXP | Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and exe… | Patch early | 6.8 medium | 11.4% | 2010-03-23 |
| CVE-2012-5627 EXP | Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the… | Patch early | 4.0 medium | 11.4% | 2013-10-01 |
| CVE-2003-0276 EXP | Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request wit… | Patch early | 5.0 medium | 11.4% | 2003-06-16 |
| CVE-2006-5295 EXP | Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service crash) via a crafted Compress… | Patch early | 5.0 medium | 11.4% | 2006-10-16 |
| CVE-2012-0551 EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE 7 update 4 and earlier and 6 update 32 and earlier, and the GlassFis… | Patch early | 5.8 medium | 11.4% | 2012-05-03 |
| CVE-2019-15889 EXP | The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_d… | Patch early | 6.1 medium | 11.4% | 2019-09-03 |
| CVE-2001-0643 EXP | Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into… | Patch early | 5.0 medium | 11.4% | 2001-09-20 |
| CVE-2007-0816 EXP | The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to c… | Patch early | 5.0 medium | 11.4% | 2007-02-07 |
| CVE-2015-3081 EXP | Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, A… | Patch early | 4.3 medium | 11.4% | 2015-05-13 |
| CVE-2007-5925 EXP | The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to… | Patch early | 4.0 medium | 11.4% | 2007-11-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt