CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-0333 EXP | lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data… | Patch early | 7.5 high | 95.3% | 2013-01-30 |
| CVE-2021-22911 EXP | A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulti… | Patch early | 9.8 critical | 95.2% | 2021-05-27 |
| CVE-2008-1447 EXP | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, a… | Patch early | 6.8 medium | 95.2% | 2008-07-08 |
| CVE-2006-3918 EXP | http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, an… | Patch early | 4.3 medium | 95.1% | 2006-07-28 |
| CVE-2002-0840 EXP | Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off"… | Patch early | 6.8 medium | 95.1% | 2002-10-11 |
| CVE-2024-0204 EXP | Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal. | Patch early | 9.8 critical | 95.1% | 2024-01-22 |
| CVE-2017-9798 EXP | Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd… | Patch early | 7.5 high | 95% | 2017-09-18 |
| CVE-2011-4862 EXP | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, H… | Patch early | 10.0 high | 95% | 2011-12-25 |
| CVE-2002-0392 EXP | Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via… | Patch early | 7.5 high | 94.9% | 2002-07-03 |
| CVE-2015-5531 EXP | Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to sna… | Patch early | 5.0 medium | 94.8% | 2015-08-17 |
| CVE-2001-0797 EXP | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of argum… | Patch early | 10.0 high | 94.7% | 2001-12-12 |
| CVE-2013-2248 EXP | Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and condu… | Patch early | 5.8 medium | 94.7% | 2013-07-20 |
| CVE-2020-24186 EXP | A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to up… | Patch early | 10.0 critical | 94.6% | 2020-08-24 |
| CVE-2016-5674 EXP | __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 throu… | Patch early | 9.8 critical | 94.6% | 2016-08-31 |
| CVE-2014-0515 EXP | Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on… | Patch early | 10.0 high | 94.6% | 2014-04-29 |
| CVE-2015-0235 EXP | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attac… | Patch early | 10.0 high | 94.6% | 2015-01-28 |
| CVE-2010-3972 EXP | Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Informati… | Patch early | 10.0 high | 94.5% | 2010-12-23 |
| CVE-2015-7857 EXP | SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5… | Patch early | 7.5 high | 94.5% | 2015-10-29 |
| CVE-2009-0580 EXP | Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enume… | Patch early | 4.3 medium | 94.4% | 2009-06-05 |
| CVE-2021-46422 EXP | Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authe… | Patch early | 9.8 critical | 94.3% | 2022-04-27 |
| CVE-2018-3245 EXP | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… | Patch early | 9.8 critical | 94.3% | 2018-10-17 |
| CVE-2016-2004 EXP | HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors rela… | Patch early | 9.8 critical | 94.3% | 2016-04-21 |
| CVE-2023-30258 EXP | Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP… | Patch early | 9.8 critical | 94.3% | 2023-06-23 |
| CVE-2010-0425 EXP | modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when runnin… | Patch early | 10.0 high | 94.2% | 2010-03-05 |
| CVE-2010-3964 EXP | Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document… | Patch early | 7.5 high | 94.2% | 2010-12-16 |
| CVE-2016-1524 EXP | Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary… | Patch early | 9.6 critical | 94.1% | 2016-02-13 |
| CVE-2024-8856 EXP | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the… | Patch early | 9.8 critical | 94% | 2024-11-16 |
| CVE-2020-17506 EXP | Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injectio… | Patch early | 9.8 critical | 94% | 2020-08-12 |
| CVE-2017-5753 EXP | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wit… | Patch early | 5.6 medium | 93.8% | 2018-01-04 |
| CVE-2018-1335 EXP | From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the comm… | Patch early | 8.1 high | 93.8% | 2018-04-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt