CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,436 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-28164 EXP | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to ac… | Patch early | 5.3 medium | 82.4% | 2021-04-01 |
| CVE-2009-2521 EXP | Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users… | Patch early | 5.0 medium | 82.3% | 2009-09-04 |
| CVE-2014-9016 EXP | The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote… | Patch early | 5.0 medium | 82.2% | 2014-11-24 |
| CVE-2012-0053 EXP | protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) e… | Patch early | 4.3 medium | 82.2% | 2012-01-28 |
| CVE-2017-0038 EXP | gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S… | Patch early | 5.5 medium | 82.1% | 2017-02-20 |
| CVE-2019-10092 EXP | In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the… | Patch early | 6.1 medium | 81.5% | 2019-09-26 |
| CVE-2013-4212 EXP | Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via… | Patch early | 6.8 medium | 81.1% | 2013-12-07 |
| CVE-2007-6203 EXP | Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request… | Patch early | 4.3 medium | 80.7% | 2007-12-03 |
| CVE-2013-4123 EXP | client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port num… | Patch early | 5.0 medium | 80.5% | 2013-09-16 |
| CVE-2004-0230 EXP | TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to… | Patch early | 5.0 medium | 80.3% | 2004-08-18 |
| CVE-2009-1386 EXP | ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS Chan… | Patch early | 5.0 medium | 80.1% | 2009-06-04 |
| CVE-2004-0790 EXP | Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages,… | Patch early | 5.0 medium | 80.1% | 2005-04-12 |
| CVE-2000-0246 EXP | IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to… | Patch early | 5.0 medium | 80% | 2000-03-30 |
| CVE-2016-0491 EXP | Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows rem… | Patch early | 6.4 medium | 79.9% | 2016-01-21 |
| CVE-2011-4858 EXP | Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trig… | Patch early | 5.0 medium | 79.7% | 2012-01-05 |
| CVE-2023-2745 EXP | WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated at… | Patch early | 5.4 medium | 79.5% | 2023-05-17 |
| CVE-2014-6034 EXP | Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8… | Patch early | 5.0 medium | 79% | 2014-12-04 |
| CVE-2019-1622 EXP | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to r… | Patch early | 5.3 medium | 78.9% | 2019-06-27 |
| CVE-2000-0302 EXP | Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument t… | Patch early | 5.0 medium | 78.6% | 2000-03-31 |
| CVE-2006-3392 EXP | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary fi… | Patch early | 5.0 medium | 78.3% | 2006-07-06 |
| CVE-2010-1587 EXP | The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash s… | Patch early | 5.0 medium | 78% | 2010-04-28 |
| CVE-2007-2449 EXP | Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 t… | Patch early | 4.3 medium | 77.4% | 2007-06-14 |
| CVE-2024-23334 EXP | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it i… | Patch early | 5.9 medium | 76.9% | 2024-01-29 |
| CVE-2003-0190 EXP | OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows re… | Patch early | 5.0 medium | 76.8% | 2003-05-12 |
| CVE-2017-9554 EXP | An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumera… | Patch early | 5.3 medium | 76.7% | 2017-07-24 |
| CVE-2005-3081 EXP | wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE command. | Patch early | 4.6 medium | 76.6% | 2005-09-27 |
| CVE-2022-44267 EXP | ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for… | Patch early | 6.5 medium | 76.6% | 2023-02-06 |
| CVE-2010-2156 EXP | ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID. | Patch early | 5.0 medium | 76.4% | 2010-06-07 |
| CVE-2021-22145 EXP | A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary querie… | Patch early | 6.5 medium | 76.2% | 2021-07-21 |
| CVE-2008-1232 EXP | Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers… | Patch early | 4.3 medium | 75.9% | 2008-08-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt