Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,123 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 34 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2011-4723 | D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability | KEVMEDIUM 5.7EPSS 2.98% | 20 December 2011 |
| CVE-2011-2462 | Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability | KEVCRITICAL 9.8EPSS 86.6% | 7 December 2011 |
| CVE-2011-3402 | Microsoft Windows Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 78.3% | 4 November 2011 |
| CVE-2011-3544 | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 96.7% | 19 October 2011 |
| CVE-2011-2005 | Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability | KEVHIGH 7.8EPSS 31.8% | 12 October 2011 |
| CVE-2011-1889 | Microsoft Forefront TMG Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 48.4% | 16 June 2011 |
| CVE-2011-1823 | Android OS Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 41.6% | 9 June 2011 |
| CVE-2011-0611 | Adobe Flash Player Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 99.4% | 13 April 2011 |
| CVE-2011-0609 | Adobe Flash Player Unspecified Vulnerability | KEVHIGH 7.8EPSS 66.8% | 15 March 2011 |
| CVE-2010-4345 | Exim Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 18.1% | 14 December 2010 |
| CVE-2010-4344 | Exim Heap-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 71.9% | 14 December 2010 |
| CVE-2010-3904 | Linux Kernel Improper Input Validation Vulnerability | KEVHIGH 7.8EPSS 14.6% | 6 December 2010 |
| CVE-2010-4398 | Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 8.66% | 6 December 2010 |
| CVE-2010-3333 | Microsoft Office Stack-based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 89.5% | 10 November 2010 |
| CVE-2010-2572 | Microsoft PowerPoint Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 62.6% | 10 November 2010 |
| CVE-2010-3962 | Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability | KEVHIGH 8.1EPSS 96.9% | 5 November 2010 |
| CVE-2010-3765 | Mozilla Multiple Products Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 83.3% | 28 October 2010 |
| CVE-2010-2883 | Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability | KEVHIGH 7.3EPSS 82.5% | 9 September 2010 |
| CVE-2010-3035 | Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 5.56% | 30 August 2010 |
| CVE-2010-2861 | Adobe ColdFusion Directory Traversal Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 11 August 2010 |
| CVE-2010-1871 | Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 83.4% | 5 August 2010 |
| CVE-2010-2568 | Microsoft Windows Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 91.3% | 22 July 2010 |
| CVE-2010-1297 | Adobe Flash Player Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 82.4% | 8 June 2010 |
| CVE-2010-1428 | Red Hat JBoss Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 62.3% | 28 April 2010 |
| CVE-2010-0738 | Red Hat JBoss Authentication Bypass Vulnerability | KEVMEDIUM 5.3EPSS 79.4% | 28 April 2010 |
| CVE-2010-0840 | Oracle JRE Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 96.3% | 1 April 2010 |
| CVE-2010-0806 | Microsoft Internet Explorer Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 82.2% | 10 March 2010 |
| CVE-2010-0188 | Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability | KEVHIGH 7.8EPSS 88.2% | 22 February 2010 |
| CVE-2009-3960 | Adobe BlazeDS Information Disclosure Vulnerability | KEVMEDIUM 6.5EPSS 90.0% | 15 February 2010 |
| CVE-2010-0232 | Microsoft Windows Kernel Exception Handler Vulnerability | KEVHIGH 7.8EPSS 29.3% | 21 January 2010 |
| CVE-2010-0249 | Microsoft Internet Explorer Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 91.9% | 15 January 2010 |
| CVE-2009-3953 | Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 83.9% | 13 January 2010 |
| CVE-2009-4324 | Adobe Acrobat and Reader Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 81.9% | 15 December 2009 |
| CVE-2009-3129 | Microsoft Excel Featheader Record Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 85.7% | 11 November 2009 |
| CVE-2009-3459 | Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 86.6% | 13 October 2009 |
| CVE-2009-2055 | Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability | KEVMEDIUM 5.9EPSS 3.33% | 19 August 2009 |
| CVE-2009-1862 | Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability | KEVHIGH 7.8EPSS 25.0% | 23 July 2009 |
| CVE-2008-0015 | Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 76.7% | 7 July 2009 |
| CVE-2009-1123 | Microsoft Windows Improper Input Validation Vulnerability | KEVHIGH 7.8EPSS 4.92% | 10 June 2009 |
| CVE-2009-0557 | Microsoft Office Object Record Corruption Vulnerability | KEVHIGH 7.8EPSS 58.6% | 10 June 2009 |
| CVE-2009-0563 | Microsoft Office Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 63.1% | 10 June 2009 |
| CVE-2009-1537 | Microsoft DirectX NULL Byte Overwrite Vulnerability | KEVHIGH 8.8EPSS 51.2% | 29 May 2009 |
| CVE-2009-0556 | Microsoft Office PowerPoint Code Injection Vulnerability | KEVHIGH 8.8EPSS 67.5% | 3 April 2009 |
| CVE-2009-1151 | phpMyAdmin Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 96.6% | 26 March 2009 |
| CVE-2009-0927 | Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 96.6% | 19 March 2009 |
| CVE-2009-0238 | Microsoft Office Remote Code Execution | KEVHIGH 8.8EPSS 43.2% | 25 February 2009 |
| CVE-2008-2992 | Adobe Reader and Acrobat Input Validation Vulnerability | KEVHIGH 7.8EPSS 98.5% | 4 November 2008 |
| CVE-2008-4250 | Microsoft Windows Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 98.8% | 23 October 2008 |
| CVE-2008-4128 | Cisco IOS Cross-Site Request Forgery Vulnerability | KEVMEDIUM 4.3EPSS 33.9% | 18 September 2008 |
| CVE-2008-3431 | Oracle VirtualBox Insufficient Input Validation Vulnerability | KEVHIGH 8.8EPSS 6.93% | 5 August 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.