CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,502 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-0333 EXP | lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data… | Patch early | 7.5 high | 95.3% | 2013-01-30 |
| CVE-2017-9798 EXP | Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd… | Patch early | 7.5 high | 95% | 2017-09-18 |
| CVE-2011-4862 EXP | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, H… | Patch early | 10.0 high | 95% | 2011-12-25 |
| CVE-2002-0392 EXP | Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via… | Patch early | 7.5 high | 94.9% | 2002-07-03 |
| CVE-2001-0797 EXP | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of argum… | Patch early | 10.0 high | 94.7% | 2001-12-12 |
| CVE-2014-0515 EXP | Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on… | Patch early | 10.0 high | 94.6% | 2014-04-29 |
| CVE-2015-0235 EXP | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attac… | Patch early | 10.0 high | 94.6% | 2015-01-28 |
| CVE-2010-3972 EXP | Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Informati… | Patch early | 10.0 high | 94.5% | 2010-12-23 |
| CVE-2015-7857 EXP | SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5… | Patch early | 7.5 high | 94.5% | 2015-10-29 |
| CVE-2010-0425 EXP | modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when runnin… | Patch early | 10.0 high | 94.2% | 2010-03-05 |
| CVE-2010-3964 EXP | Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document… | Patch early | 7.5 high | 94.2% | 2010-12-16 |
| CVE-2018-1335 EXP | From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the comm… | Patch early | 8.1 high | 93.8% | 2018-04-25 |
| CVE-2020-8617 EXP | Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successful… | Patch early | 7.5 high | 93.4% | 2020-05-19 |
| CVE-2016-3081 EXP | Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execu… | Patch early | 8.1 high | 93.4% | 2016-04-26 |
| CVE-2005-1983 EXP | Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to exe… | Patch early | 10.0 high | 93% | 2005-08-10 |
| CVE-2022-21371 EXP | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 1… | Patch early | 7.5 high | 92.6% | 2022-01-19 |
| CVE-2018-16509 EXP | An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions… | Patch early | 7.8 high | 92.5% | 2018-09-05 |
| CVE-2006-2369 EXP | RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a… | Patch early | 7.5 high | 92.4% | 2006-05-15 |
| CVE-2009-3103 EXP | Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, an… | Patch early | 10.0 high | 92.3% | 2009-09-08 |
| CVE-2015-0359 EXP | Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457… | Patch early | 10.0 high | 92.1% | 2015-04-14 |
| CVE-2018-14912 EXP | cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgi… | Patch early | 7.5 high | 92% | 2018-08-03 |
| CVE-2019-0227 EXP | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits… | Patch early | 7.5 high | 91.9% | 2019-05-01 |
| CVE-2001-0414 EXP | Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute… | Patch early | 10.0 high | 91.7% | 2001-06-18 |
| CVE-2019-9193 EXP | In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute ar… | Patch early | 7.2 high | 91.7% | 2019-04-01 |
| CVE-2008-0226 EXP | Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code v… | Patch early | 7.5 high | 91.6% | 2008-01-10 |
| CVE-2017-16806 EXP | The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory traversal. | Patch early | 7.5 high | 91.5% | 2017-11-13 |
| CVE-2014-0569 EXP | Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Ado… | Patch early | 9.3 high | 91.3% | 2014-10-15 |
| CVE-2010-4221 EXP | Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbit… | Patch early | 10.0 high | 91.3% | 2010-11-09 |
| CVE-2015-5477 EXP | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and… | Patch early | 7.8 high | 91.3% | 2015-07-29 |
| CVE-2020-8654 EXP | An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitra… | Patch early | 8.8 high | 91.2% | 2020-02-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt