CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,596 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
25,086 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-3587 EXP | Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to exec… | Patch early | 9.3 high | 78.1% | 2011-10-10 |
| CVE-2010-1587 EXP | The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash s… | Patch early | 5.0 medium | 78% | 2010-04-28 |
| CVE-2007-2139 EXP | Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightS… | Patch early | 10.0 high | 78% | 2007-04-25 |
| CVE-2019-16113 EXP | Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PH… | Patch early | 8.8 high | 78% | 2019-09-08 |
| CVE-2021-39312 EXP | The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed vi… | Patch early | 7.5 high | 77.9% | 2021-12-14 |
| CVE-2013-6221 EXP | Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled,… | Patch early | 10.0 high | 77.9% | 2014-06-18 |
| CVE-2004-1561 EXP | Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers. | Patch early | 7.5 high | 77.9% | 2004-12-31 |
| CVE-2014-5005 EXP | Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via… | Patch early | 7.5 high | 77.8% | 2014-10-21 |
| CVE-2015-2797 EXP | Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0… | Patch early | 10.0 high | 77.8% | 2015-06-19 |
| CVE-2019-12840 EXP | In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data paramete… | Patch early | 8.8 high | 77.8% | 2019-06-15 |
| CVE-2014-0113 EXP | CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method,… | Patch early | 7.5 high | 77.8% | 2014-04-29 |
| CVE-2022-24734 EXP | MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctl… | Patch early | 7.2 high | 77.8% | 2022-03-09 |
| CVE-2017-1000117 EXP | A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that e… | Patch early | 8.8 high | 77.8% | 2017-10-05 |
| CVE-2010-0842 EXP | Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows rem… | Patch early | 7.5 high | 77.7% | 2010-04-01 |
| CVE-2008-2639 EXP | Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbit… | Patch early | 7.6 high | 77.7% | 2008-06-16 |
| CVE-2002-1123 EXP | Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execu… | Patch early | 7.5 high | 77.7% | 2002-09-24 |
| CVE-2018-10823 EXP | An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DW… | Patch early | 8.8 high | 77.7% | 2018-10-17 |
| CVE-2020-0609 EXP | A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target sy… | Patch early | 9.8 critical | 77.7% | 2020-01-14 |
| CVE-2007-1748 EXP | Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP… | Patch early | 10.0 high | 77.7% | 2007-04-13 |
| CVE-2007-2446 EXP | Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via… | Patch early | 10.0 high | 77.7% | 2007-05-14 |
| CVE-2010-1549 EXP | Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary… | Patch early | 10.0 high | 77.6% | 2010-05-07 |
| CVE-2018-9059 EXP | Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code via a malicious login request… | Patch early | 9.8 critical | 77.6% | 2018-04-20 |
| CVE-2020-13166 EXP | The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers… | Patch early | 9.8 critical | 77.6% | 2020-05-19 |
| CVE-2003-0714 EXP | The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directl… | Patch early | 7.5 high | 77.6% | 2003-11-17 |
| CVE-2013-0634 EXP | Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux,… | Patch early | 9.3 high | 77.6% | 2013-02-08 |
| CVE-2016-10176 EXP | The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This… | Patch early | 9.8 critical | 77.6% | 2017-01-30 |
| CVE-2016-0709 EXP | Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated… | Patch early | 7.2 high | 77.5% | 2016-04-11 |
| CVE-2008-2499 EXP | Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8… | Patch early | 7.5 high | 77.5% | 2008-05-29 |
| CVE-2017-14143 EXP | The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers to… | Patch early | 9.8 critical | 77.4% | 2017-09-19 |
| CVE-2020-8012 EXP | CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller)… | Patch early | 9.8 critical | 77.4% | 2020-02-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt