CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,514 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-3704 EXP | The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which all… | Patch early | 7.5 high | 100% | 2014-10-16 |
| CVE-2015-7297 EXP | SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different… | Patch early | 7.5 high | 100% | 2015-10-29 |
| CVE-2022-42889 EXP | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolati… | Patch early | 9.8 critical | 99.9% | 2022-10-13 |
| CVE-2019-0232 EXP | When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93… | Patch early | 8.1 high | 99.9% | 2019-04-15 |
| CVE-2020-13379 EXP | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/clien… | Patch early | 8.2 high | 99.9% | 2020-06-03 |
| CVE-2017-12635 EXP | Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.… | Patch early | 9.8 critical | 99.8% | 2017-11-14 |
| CVE-2017-8917 EXP | SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors. | Patch early | 9.8 critical | 99.8% | 2017-05-17 |
| CVE-2008-2938 EXP | Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 a… | Patch early | 4.3 medium | 99.7% | 2008-08-13 |
| CVE-2020-10220 EXP | An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter. | Patch early | 9.8 critical | 99.7% | 2020-03-07 |
| CVE-2023-27372 EXP | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,… | Patch early | 9.8 critical | 99.7% | 2023-02-28 |
| CVE-2022-37061 EXP | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject an… | Patch early | 9.8 critical | 99.6% | 2022-08-18 |
| CVE-2020-14181 EXP | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabilit… | Patch early | 5.3 medium | 99.6% | 2020-09-17 |
| CVE-2020-16040 EXP | Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a craft… | Patch early | 6.5 medium | 99.6% | 2021-01-08 |
| CVE-2014-0094 EXP | The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is p… | Patch early | 5.0 medium | 99.6% | 2014-03-11 |
| CVE-2024-6387 EXP | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals… | Patch early | 8.1 high | 99.5% | 2024-07-01 |
| CVE-2017-1000028 EXP | Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can b… | Patch early | 7.5 high | 99.5% | 2017-07-17 |
| CVE-2013-0156 EXP | active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not… | Patch early | 7.5 high | 99.4% | 2013-01-13 |
| CVE-2023-32560 EXP | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code executi… | Patch early | 9.8 critical | 99.4% | 2023-08-10 |
| CVE-2025-1974 EXP | A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve a… | Patch early | 9.8 critical | 99.4% | 2025-03-25 |
| CVE-2021-34429 EXP | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of th… | Patch early | 5.3 medium | 99.3% | 2021-07-15 |
| CVE-2017-12542 EXP | A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found. | Patch early | 10.0 critical | 99.3% | 2018-02-15 |
| CVE-2023-23333 EXP | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions throug… | Patch early | 9.8 critical | 99.3% | 2023-02-06 |
| CVE-2025-29927 EXP | Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 1… | Patch early | 9.1 critical | 99.2% | 2025-03-21 |
| CVE-2020-11022 EXP | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation… | Patch early | 6.9 medium | 99.2% | 2020-04-29 |
| CVE-2015-1538 EXP | Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote… | Patch early | 10.0 high | 99.1% | 2015-10-01 |
| CVE-2022-24637 EXP | Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin… | Patch early | 9.8 critical | 99.1% | 2022-03-18 |
| CVE-2014-0114 EXP | Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring common… | Patch early | 7.5 high | 99% | 2014-04-30 |
| CVE-2020-9496 EXP | XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 | Patch early | 6.1 medium | 98.9% | 2020-07-15 |
| CVE-2011-3192 EXP | The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of serv… | Patch early | 7.8 high | 98.8% | 2011-08-29 |
| CVE-2020-7209 EXP | LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2. | Patch early | 9.8 critical | 98.8% | 2020-02-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt