CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,152 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
319,060 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-14425 EXP | Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass th… | Patch early | 7.8 high | 41.1% | 2020-11-02 |
| CVE-2016-0122 EXP | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel V… | Patch early | 7.8 high | 41.1% | 2016-04-12 |
| CVE-2006-3059 EXP | Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors… | Patch early | 9.3 high | 41.1% | 2006-06-17 |
| CVE-2022-29548 EXP | A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, an… | Patch early | 4.6 medium | 41.1% | 2022-04-21 |
| CVE-2015-2065 EXP | SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin before 2.8 for WordPress allows… | Patch early | 7.5 high | 41.1% | 2015-02-24 |
| CVE-2015-3083 EXP | Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17… | Patch early | 6.4 medium | 41.1% | 2015-05-13 |
| CVE-2007-5654 EXP | LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new… | Patch early | 5.0 medium | 41.1% | 2007-10-23 |
| CVE-2005-0416 EXP | The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers… | Patch early | 7.5 high | 41% | 2005-04-27 |
| CVE-2019-12593 EXP | IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory tra… | Patch early | 7.5 high | 41% | 2019-06-03 |
| CVE-2015-0097 EXP | Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execute… | Patch early | 9.3 high | 40.9% | 2015-03-11 |
| CVE-2003-0434 EXP | Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters i… | Patch early | 7.5 high | 40.9% | 2003-07-24 |
| CVE-2018-14493 EXP | Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HT… | Patch early | 6.1 medium | 40.9% | 2018-07-25 |
| CVE-2015-5621 EXP | The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when pars… | Patch early | 7.5 high | 40.9% | 2015-08-19 |
| CVE-2014-8676 EXP | Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence… | Patch early | 5.3 medium | 40.8% | 2017-08-31 |
| CVE-2017-7442 EXP | Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences. | Patch early | 8.8 high | 40.7% | 2017-08-03 |
| CVE-2015-8044 EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux,… | Patch early | 10.0 high | 40.7% | 2015-11-11 |
| CVE-2008-5002 EXP | Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allo… | Patch early | 9.3 high | 40.7% | 2008-11-10 |
| CVE-2012-5223 EXP | The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert… | Patch early | 7.5 high | 40.5% | 2012-10-01 |
| CVE-2007-2938 EXP | Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is us… | Patch early | 10.0 high | 40.5% | 2007-05-31 |
| CVE-2009-0565 EXP | Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Conver… | Patch early | 9.3 high | 40.5% | 2009-06-10 |
| CVE-2013-1412 EXP | DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a… | Patch early | 7.5 high | 40.5% | 2014-06-02 |
| CVE-2011-0517 EXP | Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows remote attackers to cause a de… | Patch early | 9.3 high | 40.5% | 2011-01-20 |
| CVE-2007-1286 EXP | Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize fun… | Patch early | 6.8 medium | 40.4% | 2007-03-06 |
| CVE-2015-3118 EXP | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.4… | Patch early | 10.0 high | 40.4% | 2015-07-09 |
| CVE-2006-3493 EXP | Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office… | Patch early | 5.1 medium | 40.4% | 2006-07-10 |
| CVE-2007-3147 EXP | Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute ar… | Patch early | 9.3 high | 40.4% | 2007-06-11 |
| CVE-2014-0980 EXP | Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI file. | Patch early | 9.3 high | 40.4% | 2014-02-11 |
| CVE-2013-0136 EXP | Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to… | Patch early | 8.5 high | 40.3% | 2013-06-01 |
| CVE-2006-2111 EXP | A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections wit… | Patch early | 4.3 medium | 40.3% | 2006-05-01 |
| CVE-2007-4475 EXP | Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers to… | Patch early | 9.3 high | 40.3% | 2009-04-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt