CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,502 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-6352 KEV EXP | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows R… | Patch first | 7.8 high | 77.5% | 2014-10-22 |
| CVE-2014-1761 KEV EXP | Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automati… | Patch first | 7.8 high | 77.5% | 2014-03-25 |
| CVE-2013-3897 KEV EXP | Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute… | Patch first | 8.8 high | 77.3% | 2013-10-09 |
| CVE-2019-1429 KEV EXP | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin… | Patch first | 7.5 high | 77.3% | 2019-11-12 |
| CVE-2020-10221 KEV EXP | lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the… | Patch first | 8.8 high | 77.1% | 2020-03-08 |
| CVE-2019-15949 KEV EXP | Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin u… | Patch first | 8.8 high | 77% | 2019-09-05 |
| CVE-2018-15133 KEV EXP | In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially un… | Patch first | 8.1 high | 76.8% | 2018-08-09 |
| CVE-2016-3718 KEV EXP | The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (S… | Patch first | 5.5 medium | 76.7% | 2016-05-05 |
| CVE-2008-0015 KEV EXP | Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX… | Patch first | 8.8 high | 76.7% | 2009-07-07 |
| CVE-2018-15811 KEV EXP | DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. | Patch first | 7.5 high | 76.1% | 2019-07-03 |
| CVE-2015-0016 KEV EXP | Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP… | Patch first | 7.8 high | 75.8% | 2015-01-13 |
| CVE-2012-0391 KEV EXP | The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for… | Patch first | 9.8 critical | 75.6% | 2012-01-08 |
| CVE-2016-3715 KEV EXP | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. | Patch first | 5.5 medium | 75.3% | 2016-05-05 |
| CVE-2017-9248 KEV EXP | Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.… | Patch first | 9.8 critical | 75.1% | 2017-07-03 |
| CVE-2014-0780 KEV EXP | Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative password… | Patch first | 9.8 critical | 74.7% | 2014-04-25 |
| CVE-2005-2773 KEV EXP | HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node param… | Patch first | 9.8 critical | 74.6% | 2005-09-02 |
| CVE-2018-8298 KEV EXP | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory C… | Patch first | 7.5 high | 74.5% | 2018-07-11 |
| CVE-2019-1458 KEV EXP | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation… | Patch first | 7.8 high | 74.3% | 2019-12-10 |
| CVE-2013-2551 KEV EXP | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that… | Patch first | 8.8 high | 74.1% | 2013-03-11 |
| CVE-2019-12991 KEV EXP | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). | Patch first | 8.8 high | 74.1% | 2019-07-16 |
| CVE-2018-18325 KEV EXP | DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete… | Patch first | 7.5 high | 73.9% | 2019-07-03 |
| CVE-2015-3043 KEV EXP | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to… | Patch first | 9.8 critical | 73.9% | 2015-04-14 |
| CVE-2013-3918 KEV EXP | The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2,… | Patch first | 8.8 high | 73.7% | 2013-11-12 |
| CVE-2018-8120 KEV EXP | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation… | Patch first | 7.0 high | 73.4% | 2018-05-09 |
| CVE-2024-37383 KEV EXP | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. | Patch first | 6.1 medium | 73.3% | 2024-06-07 |
| CVE-2018-0824 KEV EXP | A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM fo… | Patch first | 8.8 high | 73.2% | 2018-05-09 |
| CVE-2017-6316 KEV EXP | Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On… | Patch first | 9.8 critical | 73% | 2017-07-20 |
| CVE-2019-9978 KEV EXP | The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as explo… | Patch first | 6.1 medium | 72.9% | 2019-03-24 |
| CVE-2018-7841 KEV EXP | A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper se… | Patch first | 9.8 critical | 72.7% | 2019-05-22 |
| CVE-2017-6334 KEV EXP | dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell… | Patch first | 8.8 high | 72.6% | 2017-03-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt