CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,502 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
185,350 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-0780 KEV EXP | Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative password… | Patch first | 9.8 critical | 74.7% | 2014-04-25 |
| CVE-2005-2773 KEV EXP | HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node param… | Patch first | 9.8 critical | 74.6% | 2005-09-02 |
| CVE-2018-8298 KEV EXP | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory C… | Patch first | 7.5 high | 74.5% | 2018-07-11 |
| CVE-2019-1458 KEV EXP | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation… | Patch first | 7.8 high | 74.3% | 2019-12-10 |
| CVE-2013-2551 KEV EXP | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that… | Patch first | 8.8 high | 74.1% | 2013-03-11 |
| CVE-2019-12991 KEV EXP | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). | Patch first | 8.8 high | 74.1% | 2019-07-16 |
| CVE-2018-18325 KEV EXP | DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete… | Patch first | 7.5 high | 73.9% | 2019-07-03 |
| CVE-2015-3043 KEV EXP | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to… | Patch first | 9.8 critical | 73.9% | 2015-04-14 |
| CVE-2013-3918 KEV EXP | The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2,… | Patch first | 8.8 high | 73.7% | 2013-11-12 |
| CVE-2018-8120 KEV EXP | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation… | Patch first | 7.0 high | 73.4% | 2018-05-09 |
| CVE-2018-0824 KEV EXP | A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM fo… | Patch first | 8.8 high | 73.2% | 2018-05-09 |
| CVE-2017-6316 KEV EXP | Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On… | Patch first | 9.8 critical | 73% | 2017-07-20 |
| CVE-2018-7841 KEV EXP | A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper se… | Patch first | 9.8 critical | 72.7% | 2019-05-22 |
| CVE-2017-6334 KEV EXP | dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell… | Patch first | 8.8 high | 72.6% | 2017-03-06 |
| CVE-2019-2215 KEV EXP | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this… | Patch first | 7.8 high | 72.1% | 2019-10-11 |
| CVE-2017-8540 KEV EXP | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… | Patch first | 7.8 high | 71.9% | 2017-05-26 |
| CVE-2010-4344 KEV EXP | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMT… | Patch first | 9.8 critical | 71.7% | 2010-12-14 |
| CVE-2016-2386 KEV EXP | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspeci… | Patch first | 9.8 critical | 71.5% | 2016-02-16 |
| CVE-2013-3163 KEV EXP | Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch first | 8.8 high | 70.7% | 2013-07-10 |
| CVE-2012-1535 KEV EXP | Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers t… | Patch first | 7.8 high | 70.4% | 2012-08-15 |
| CVE-2017-6736 KEV EXP | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authent… | Patch first | 8.8 high | 70.4% | 2017-07-17 |
| CVE-2018-8453 KEV EXP | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation… | Patch first | 7.8 high | 70% | 2018-10-10 |
| CVE-2016-0185 KEV EXP | Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Cent… | Patch first | 7.8 high | 69.8% | 2016-05-11 |
| CVE-2013-1690 KEV EXP | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle… | Patch first | 8.8 high | 69% | 2013-06-26 |
| CVE-2017-6077 KEV EXP | ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metac… | Patch first | 9.8 critical | 68.7% | 2017-02-22 |
| CVE-2015-4495 KEV EXP | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same… | Patch first | 8.8 high | 68.6% | 2015-08-08 |
| CVE-2019-18426 KEV EXP | A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site script… | Patch first | 8.2 high | 67.9% | 2020-01-21 |
| CVE-2016-4657 KEV EXP | WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web… | Patch first | 8.8 high | 66.8% | 2016-08-25 |
| CVE-2013-2729 KEV EXP | Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code… | Patch first | 9.8 critical | 66.6% | 2013-05-16 |
| CVE-2013-0629 KEV EXP | Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vecto… | Patch first | 7.5 high | 65.8% | 2013-01-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt