CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,596 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-42327 EXP | A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerabilit… | Patch early | 9.9 critical | 78.7% | 2024-11-27 |
| CVE-2014-3791 EXP | Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code via a long string in a cookie… | Patch early | 10.0 high | 78.7% | 2014-05-20 |
| CVE-2012-5088 EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect c… | Patch early | 10.0 high | 78.7% | 2012-10-16 |
| CVE-2019-15954 EXP | An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on th… | Patch early | 9.9 critical | 78.7% | 2019-09-05 |
| CVE-2006-3677 EXP | Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the… | Patch early | 7.5 high | 78.7% | 2006-07-27 |
| CVE-2000-0917 EXP | Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. | Patch early | 10.0 high | 78.7% | 2000-12-19 |
| CVE-2020-5791 EXP | Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating sy… | Patch early | 7.2 high | 78.6% | 2020-10-20 |
| CVE-2014-7205 EXP | Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for N… | Patch early | 10.0 high | 78.6% | 2014-10-08 |
| CVE-2000-0302 EXP | Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument t… | Patch early | 5.0 medium | 78.6% | 2000-03-31 |
| CVE-2013-4786 EXP | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password… | Patch early | 7.5 high | 78.6% | 2013-07-08 |
| CVE-2010-2063 EXP | Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote… | Patch early | 7.5 high | 78.6% | 2010-06-17 |
| CVE-2017-0070 EXP | A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft brows… | Patch early | 7.5 high | 78.5% | 2017-03-17 |
| CVE-2009-4189 EXP | HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code via a sess… | Patch early | 10.0 high | 78.5% | 2009-12-03 |
| CVE-2020-35665 EXP | An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include… | Patch early | 9.8 critical | 78.5% | 2020-12-23 |
| CVE-2018-0776 EXP | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… | Patch early | 7.5 high | 78.4% | 2018-01-04 |
| CVE-2018-0770 EXP | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… | Patch early | 7.5 high | 78.4% | 2018-01-04 |
| CVE-2018-0777 EXP | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the… | Patch early | 7.5 high | 78.4% | 2018-01-04 |
| CVE-2014-5301 EXP | Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. | Patch early | 8.8 high | 78.4% | 2017-08-28 |
| CVE-2001-0098 EXP | Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." stri… | Patch early | 10.0 high | 78.4% | 2001-02-12 |
| CVE-2003-0780 EXP | Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to ex… | Patch early | 9.0 high | 78.4% | 2003-09-22 |
| CVE-2025-2294 EXP | The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_t… | Patch early | 9.8 critical | 78.4% | 2025-03-28 |
| CVE-2019-9851 EXP | LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained w… | Patch early | 9.8 critical | 78.3% | 2019-08-15 |
| CVE-2018-10583 EXP | An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB con… | Patch early | 7.5 high | 78.3% | 2018-05-01 |
| CVE-2006-3392 EXP | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary fi… | Patch early | 5.0 medium | 78.3% | 2006-07-06 |
| CVE-2017-17215 EXP | Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 3… | Patch early | 8.8 high | 78.3% | 2018-03-20 |
| CVE-2017-12478 EXP | It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not… | Patch early | 9.8 critical | 78.3% | 2017-08-07 |
| CVE-2020-11108 EXP | The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution b… | Patch early | 8.8 high | 78.3% | 2020-05-11 |
| CVE-2009-3068 EXP | Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute a… | Patch early | 9.3 high | 78.2% | 2009-09-04 |
| CVE-2003-0466 EXP | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demons… | Patch early | 9.8 critical | 78.1% | 2003-08-27 |
| CVE-2015-0936 EXP | Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH acce… | Patch early | 9.8 critical | 78.1% | 2017-06-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt