CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-19276 EXP | OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary command… | Patch early | 9.8 critical | 98.7% | 2019-03-21 |
| CVE-2018-15473 EXP | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet… | Patch early | 5.3 medium | 98.6% | 2018-08-17 |
| CVE-2003-0352 EXP | Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 98.5% | 2003-08-18 |
| CVE-2019-5736 EXP | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain… | Patch early | 8.6 high | 98.5% | 2019-02-11 |
| CVE-2009-1122 EXP | The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attac… | Patch early | 7.5 high | 98.4% | 2009-06-10 |
| CVE-2019-1003000 EXP | A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/… | Patch early | 8.8 high | 98.4% | 2019-01-22 |
| CVE-2018-12613 EXP | An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vul… | Patch early | 8.8 high | 98.4% | 2018-06-21 |
| CVE-2018-11409 EXP | Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by… | Patch early | 5.3 medium | 98.3% | 2018-06-08 |
| CVE-2015-8562 EXP | Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP Us… | Patch early | 7.5 high | 98.3% | 2015-12-16 |
| CVE-2020-15920 EXP | There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (… | Patch early | 9.8 critical | 98.2% | 2020-07-24 |
| CVE-2012-3153 EXP | Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attacke… | Patch early | 6.4 medium | 98.2% | 2012-10-16 |
| CVE-2020-35847 EXP | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function. | Patch early | 9.8 critical | 98.2% | 2020-12-30 |
| CVE-2009-1535 EXP | The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, a… | Patch early | 7.5 high | 98.1% | 2009-06-10 |
| CVE-2019-1821 EXP | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could al… | Patch early | 8.8 high | 98.1% | 2019-05-16 |
| CVE-2007-0882 EXP | Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequen… | Patch early | 10.0 high | 98% | 2007-02-12 |
| CVE-2014-5445 EXP | Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remot… | Patch early | 5.0 medium | 98% | 2014-12-04 |
| CVE-2014-0112 EXP | ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manip… | Patch early | 7.5 high | 97.9% | 2014-04-29 |
| CVE-2018-1111 EXP | DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration… | Patch early | 7.5 high | 97.9% | 2018-05-17 |
| CVE-2023-6553 EXP | The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-… | Patch early | 9.8 critical | 97.8% | 2023-12-15 |
| CVE-2022-21661 EXP | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Qu… | Patch early | 8.0 high | 97.8% | 2022-01-06 |
| CVE-2016-10045 EXP | The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arb… | Patch early | 9.8 critical | 97.7% | 2016-12-30 |
| CVE-2018-15745 EXP | Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTP… | Patch early | 7.5 high | 97.7% | 2018-08-30 |
| CVE-2019-16662 EXP | An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php becau… | Patch early | 9.8 critical | 97.7% | 2019-10-28 |
| CVE-2018-11784 EXP | When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. r… | Patch early | 4.3 medium | 97.7% | 2018-10-04 |
| CVE-2023-0315 EXP | Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. | Patch early | 8.8 high | 97.7% | 2023-01-16 |
| CVE-2019-18818 EXP | strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions… | Patch early | 9.8 critical | 97.6% | 2019-11-07 |
| CVE-2013-5211 EXP | The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via f… | Patch early | 5.0 medium | 97.5% | 2014-01-02 |
| CVE-2012-0392 EXP | The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute ar… | Patch early | 6.8 medium | 97.5% | 2012-01-08 |
| CVE-2021-3378 EXP | FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then… | Patch early | 9.8 critical | 97.5% | 2021-02-01 |
| CVE-2016-6601 EXP | Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrar… | Patch early | 7.5 high | 97.4% | 2017-01-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt