CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,436 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-26
1,103 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-1389 KEV EXP | TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi… | Patch first | 8.8 high | 100% | 2023-03-15 |
| CVE-2023-44487 KEV EXP | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited… | Patch first | 7.5 high | 100% | 2023-10-10 |
| CVE-2014-0160 KEV EXP | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attack… | Patch first | 7.5 high | 100% | 2014-04-07 |
| CVE-2023-0669 KEV EXP | Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to… | Patch first | 7.2 high | 100% | 2023-02-06 |
| CVE-2021-26086 KEV EXP | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /… | Patch first | 5.3 medium | 100% | 2021-08-16 |
| CVE-2020-3452 KEV EXP | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co… | Patch first | 7.5 high | 100% | 2020-07-22 |
| CVE-2018-11776 KEV EXP | Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by us… | Patch first | 8.1 high | 100% | 2018-08-22 |
| CVE-2017-10271 KEV EXP | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected a… | Patch first | 7.5 high | 100% | 2017-10-19 |
| CVE-2021-22204 KEV EXP | Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicio… | Patch first | 6.8 medium | 100% | 2021-04-23 |
| CVE-2012-0158 KEV EXP | The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3,… | Patch first | 8.8 high | 100% | 2012-04-10 |
| CVE-2025-5777 KEV EXP | Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy… | Patch first | 7.5 high | 100% | 2025-06-17 |
| CVE-2017-12617 KEV EXP | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setti… | Patch first | 8.1 high | 100% | 2017-10-04 |
| CVE-2020-0688 KEV EXP | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microso… | Patch first | 8.8 high | 100% | 2020-02-11 |
| CVE-2021-3156 KEV EXP | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoe… | Patch first | 7.8 high | 100% | 2021-01-26 |
| CVE-2017-11882 KEV EXP | Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an a… | Patch first | 7.8 high | 99.9% | 2017-11-15 |
| CVE-2021-26085 KEV EXP | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulne… | Patch first | 5.3 medium | 99.9% | 2021-08-03 |
| CVE-2025-4427 KEV EXP | An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources with… | Patch first | 5.3 medium | 99.9% | 2025-05-13 |
| CVE-2018-0296 KEV EXP | A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affect… | Patch first | 7.5 high | 99.9% | 2018-06-07 |
| CVE-2021-27065 KEV EXP | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch first | 7.8 high | 99.9% | 2021-03-03 |
| CVE-2019-1653 KEV EXP | A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthentica… | Patch first | 7.5 high | 99.9% | 2019-01-24 |
| CVE-2023-23752 KEV EXP | An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. | Patch first | 5.3 medium | 99.8% | 2023-02-16 |
| CVE-2016-6277 KEV EXP | NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.B… | Patch first | 8.8 high | 99.8% | 2016-12-14 |
| CVE-2019-11043 KEV EXP | In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM modul… | Patch first | 8.7 high | 99.8% | 2019-10-28 |
| CVE-2017-0147 KEV EXP | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Wind… | Patch first | 7.5 high | 99.7% | 2017-03-17 |
| CVE-2017-12615 KEV EXP | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to… | Patch first | 8.1 high | 99.6% | 2017-09-19 |
| CVE-2024-28995 KEV EXP | SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. | Patch first | 8.6 high | 99.6% | 2024-06-06 |
| CVE-2014-6278 KEV EXP | GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to… | Patch first | 8.8 high | 99.6% | 2014-09-30 |
| CVE-2017-0199 KEV EXP | Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 20… | Patch first | 7.8 high | 99.5% | 2017-04-12 |
| CVE-2011-0611 KEV EXP | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and… | Patch first | 8.8 high | 99.4% | 2011-04-13 |
| CVE-2017-9805 KEV EXP | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for dese… | Patch first | 8.1 high | 99.4% | 2017-09-15 |
page 1 of 37
next →
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt