CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,483 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
12,661 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-1000028 EXP | Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can b… | Patch early | 7.5 high | 99.5% | 2017-07-17 |
| CVE-2013-0156 EXP | active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not… | Patch early | 7.5 high | 99.4% | 2013-01-13 |
| CVE-2015-1538 EXP | Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote… | Patch early | 10.0 high | 99.1% | 2015-10-01 |
| CVE-2014-0114 EXP | Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring common… | Patch early | 7.5 high | 99% | 2014-04-30 |
| CVE-2011-3192 EXP | The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of serv… | Patch early | 7.8 high | 98.8% | 2011-08-29 |
| CVE-2003-0352 EXP | Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrar… | Patch early | 7.5 high | 98.5% | 2003-08-18 |
| CVE-2019-5736 EXP | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain… | Patch early | 8.6 high | 98.5% | 2019-02-11 |
| CVE-2009-1122 EXP | The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attac… | Patch early | 7.5 high | 98.4% | 2009-06-10 |
| CVE-2019-1003000 EXP | A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/… | Patch early | 8.8 high | 98.4% | 2019-01-22 |
| CVE-2018-12613 EXP | An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vul… | Patch early | 8.8 high | 98.4% | 2018-06-21 |
| CVE-2015-8562 EXP | Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP Us… | Patch early | 7.5 high | 98.3% | 2015-12-16 |
| CVE-2009-1535 EXP | The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, a… | Patch early | 7.5 high | 98.1% | 2009-06-10 |
| CVE-2019-1821 EXP | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could al… | Patch early | 8.8 high | 98.1% | 2019-05-16 |
| CVE-2007-0882 EXP | Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequen… | Patch early | 10.0 high | 98% | 2007-02-12 |
| CVE-2014-0112 EXP | ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manip… | Patch early | 7.5 high | 97.9% | 2014-04-29 |
| CVE-2018-1111 EXP | DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration… | Patch early | 7.5 high | 97.9% | 2018-05-17 |
| CVE-2022-21661 EXP | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Qu… | Patch early | 8.0 high | 97.8% | 2022-01-06 |
| CVE-2018-15745 EXP | Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTP… | Patch early | 7.5 high | 97.7% | 2018-08-30 |
| CVE-2023-0315 EXP | Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. | Patch early | 8.8 high | 97.7% | 2023-01-16 |
| CVE-2016-6601 EXP | Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrar… | Patch early | 7.5 high | 97.4% | 2017-01-23 |
| CVE-2025-4123 EXP | A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to r… | Patch early | 7.6 high | 97% | 2025-05-22 |
| CVE-2022-0824 EXP | Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990. | Patch early | 8.8 high | 97% | 2022-03-02 |
| CVE-2015-3306 EXP | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. | Patch early | 10.0 high | 96.8% | 2015-05-18 |
| CVE-2001-0500 EXP | Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to exec… | Patch early | 10.0 high | 96.7% | 2001-07-21 |
| CVE-2006-3747 EXP | Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, a… | Patch early | 7.6 high | 96.6% | 2006-07-28 |
| CVE-2017-6090 EXP | Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary… | Patch early | 8.8 high | 96.4% | 2017-10-03 |
| CVE-2024-10914 EXP | A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulner… | Patch early | 8.1 high | 96.3% | 2024-11-06 |
| CVE-2000-0573 EXP | The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitr… | Patch early | 10.0 high | 96.2% | 2000-07-07 |
| CVE-2018-19518 EXP | University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_r… | Patch early | 7.5 high | 96.1% | 2018-11-25 |
| CVE-2019-20499 EXP | D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the W… | Patch early | 7.8 high | 95.3% | 2020-03-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt