CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,436 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-26
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-14181 EXP | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabilit… | Patch early | 5.3 medium | 99.6% | 2020-09-17 |
| CVE-2020-16040 EXP | Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a craft… | Patch early | 6.5 medium | 99.6% | 2021-01-08 |
| CVE-2014-0094 EXP | The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is p… | Patch early | 5.0 medium | 99.6% | 2014-03-11 |
| CVE-2021-34429 EXP | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of th… | Patch early | 5.3 medium | 99.3% | 2021-07-15 |
| CVE-2020-11022 EXP | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation… | Patch early | 6.9 medium | 99.2% | 2020-04-29 |
| CVE-2020-9496 EXP | XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 | Patch early | 6.1 medium | 98.9% | 2020-07-15 |
| CVE-2018-15473 EXP | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet… | Patch early | 5.3 medium | 98.6% | 2018-08-17 |
| CVE-2018-11409 EXP | Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by… | Patch early | 5.3 medium | 98.3% | 2018-06-08 |
| CVE-2012-3153 EXP | Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attacke… | Patch early | 6.4 medium | 98.2% | 2012-10-16 |
| CVE-2014-5445 EXP | Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remot… | Patch early | 5.0 medium | 98% | 2014-12-04 |
| CVE-2018-11784 EXP | When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. r… | Patch early | 4.3 medium | 97.7% | 2018-10-04 |
| CVE-2013-5211 EXP | The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via f… | Patch early | 5.0 medium | 97.5% | 2014-01-02 |
| CVE-2012-0392 EXP | The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute ar… | Patch early | 6.8 medium | 97.5% | 2012-01-08 |
| CVE-2012-2122 EXP | sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12,… | Patch early | 5.1 medium | 96.5% | 2012-06-26 |
| CVE-1999-0016 EXP | Land IP denial of service. | Patch early | 5.0 medium | 95.7% | 1997-12-01 |
| CVE-2011-0049 EXP | Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read ar… | Patch early | 5.0 medium | 95.4% | 2011-02-04 |
| CVE-2008-1447 EXP | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, a… | Patch early | 6.8 medium | 95.2% | 2008-07-08 |
| CVE-2006-3918 EXP | http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, an… | Patch early | 4.3 medium | 95.1% | 2006-07-28 |
| CVE-2002-0840 EXP | Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off"… | Patch early | 6.8 medium | 95.1% | 2002-10-11 |
| CVE-2015-5531 EXP | Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to sna… | Patch early | 5.0 medium | 94.8% | 2015-08-17 |
| CVE-2013-2248 EXP | Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and condu… | Patch early | 5.8 medium | 94.7% | 2013-07-20 |
| CVE-2009-0580 EXP | Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enume… | Patch early | 4.3 medium | 94.4% | 2009-06-05 |
| CVE-2017-5753 EXP | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wit… | Patch early | 5.6 medium | 93.8% | 2018-01-04 |
| CVE-2020-2096 EXP | Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability. | Patch early | 6.1 medium | 92.8% | 2020-01-15 |
| CVE-2019-8943 EXP | WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an a… | Patch early | 6.5 medium | 92.6% | 2019-02-20 |
| CVE-2016-0492 EXP | Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows rem… | Patch early | 6.4 medium | 92.1% | 2016-01-21 |
| CVE-2010-1870 EXP | The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly oth… | Patch early | 5.0 medium | 92% | 2010-08-17 |
| CVE-2007-0450 EXP | Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_prox… | Patch early | 5.0 medium | 90.8% | 2007-03-16 |
| CVE-2011-3368 EXP | The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with us… | Patch early | 5.0 medium | 90.7% | 2011-10-05 |
| CVE-2022-44268 EXP | ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded t… | Patch early | 6.5 medium | 89.9% | 2023-02-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt