CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,482 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
450 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-17519 KEV EXP | A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of th… | Patch first | 7.5 high | 97.8% | 2021-01-05 |
| CVE-2015-7450 KEV EXP | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote a… | Patch first | 9.8 critical | 97.8% | 2016-01-02 |
| CVE-2022-43769 KEV EXP | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property va… | Patch first | 8.8 high | 97.7% | 2023-04-03 |
| CVE-2016-3714 KEV EXP | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1… | Patch first | 8.4 high | 97.5% | 2016-05-05 |
| CVE-2024-4358 KEV EXP | In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Ser… | Patch first | 9.8 critical | 97.5% | 2024-05-29 |
| CVE-2019-9082 KEV EXP | ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefun… | Patch first | 8.8 high | 97.4% | 2019-02-24 |
| CVE-2023-27524 KEV EXP | Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KE… | Patch first | 8.9 high | 97.4% | 2023-04-24 |
| CVE-2007-3010 KEV EXP | masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbit… | Patch first | 9.8 critical | 97.4% | 2007-09-18 |
| CVE-2020-25213 KEV EXP | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames… | Patch first | 10.0 critical | 97.3% | 2020-09-09 |
| CVE-2020-14864 KEV EXP | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions… | Patch first | 7.5 high | 97.2% | 2020-10-21 |
| CVE-2020-2555 KEV EXP | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affe… | Patch first | 9.8 critical | 97.1% | 2020-01-15 |
| CVE-2019-20500 KEV EXP | D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web… | Patch first | 7.8 high | 97.1% | 2020-03-05 |
| CVE-2015-2051 KEV EXP | The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDevi… | Patch first | 8.8 high | 97.1% | 2015-02-23 |
| CVE-2019-7256 KEV EXP | Linear eMerge E3-Series devices allow Command Injections. | Patch first | 9.8 critical | 97.1% | 2019-07-02 |
| CVE-2013-0422 KEV EXP | Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiat… | Patch first | 9.8 critical | 97% | 2013-01-10 |
| CVE-2017-8291 KEV EXP | Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" s… | Patch first | 7.8 high | 97% | 2017-04-27 |
| CVE-2019-1003030 KEV EXP | A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps… | Patch first | 9.9 critical | 96.9% | 2019-03-08 |
| CVE-2019-3398 KEV EXP | Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to a… | Patch first | 8.8 high | 96.8% | 2019-04-18 |
| CVE-2010-3962 KEV EXP | Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Casca… | Patch first | 8.1 high | 96.8% | 2010-11-05 |
| CVE-2011-3544 KEV EXP | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untruste… | Patch first | 9.8 critical | 96.7% | 2011-10-19 |
| CVE-2009-0927 KEV EXP | Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arb… | Patch first | 8.8 high | 96.6% | 2009-03-19 |
| CVE-2020-11651 KEV EXP | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate… | Patch first | 9.8 critical | 96.6% | 2020-04-30 |
| CVE-2009-1151 KEV EXP | Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitra… | Patch first | 9.8 critical | 96.6% | 2009-03-26 |
| CVE-2010-0840 KEV EXP | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 a… | Patch first | 9.8 critical | 96.3% | 2010-04-01 |
| CVE-2017-17562 KEV EXP | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializin… | Patch first | 8.1 high | 96.3% | 2017-12-12 |
| CVE-2018-14847 KEV EXP | MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary f… | Patch first | 9.1 critical | 96.1% | 2018-08-02 |
| CVE-2019-20085 KEV EXP | TVT NVMS-1000 devices allow GET /.. Directory Traversal | Patch first | 7.5 high | 96.1% | 2019-12-30 |
| CVE-2022-24112 KEV EXP | An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (… | Patch first | 9.8 critical | 96.1% | 2022-02-11 |
| CVE-2015-4852 KEV EXP | The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands… | Patch first | 9.8 critical | 96% | 2015-11-18 |
| CVE-2018-20250 KEV EXP | In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.d… | Patch first | 7.8 high | 96% | 2019-02-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt