CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,436 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-26
185,314 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-3452 KEV EXP | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co… | Patch first | 7.5 high | 100% | 2020-07-22 |
| CVE-2018-7600 KEV EXP | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue… | Patch first | 9.8 critical | 100% | 2018-03-29 |
| CVE-2018-11776 KEV EXP | Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by us… | Patch first | 8.1 high | 100% | 2018-08-22 |
| CVE-2017-10271 KEV EXP | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected a… | Patch first | 7.5 high | 100% | 2017-10-19 |
| CVE-2023-42793 KEV EXP | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible | Patch first | 9.8 critical | 100% | 2023-09-19 |
| CVE-2024-4577 KEV EXP | In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use… | Patch first | 9.8 critical | 100% | 2024-06-09 |
| CVE-2019-9670 KEV EXP | mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstra… | Patch first | 9.8 critical | 100% | 2019-05-29 |
| CVE-2022-40684 KEV EXP | An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiPr… | Patch first | 9.8 critical | 100% | 2022-10-18 |
| CVE-2025-0282 KEV EXP | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for Z… | Patch first | 9.0 critical | 100% | 2025-01-08 |
| CVE-2024-4879 KEV EXP | ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerabilit… | Patch first | 9.8 critical | 100% | 2024-07-10 |
| CVE-2025-31161 KEV EXP | CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is use… | Patch first | 9.8 critical | 100% | 2025-04-03 |
| CVE-2012-0158 KEV EXP | The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3,… | Patch first | 8.8 high | 100% | 2012-04-10 |
| CVE-2014-8361 KEV EXP | The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the… | Patch first | 9.8 critical | 100% | 2015-05-01 |
| CVE-2025-5777 KEV EXP | Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy… | Patch first | 7.5 high | 100% | 2025-06-17 |
| CVE-2022-47986 KEV EXP | IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserializat… | Patch first | 9.8 critical | 100% | 2023-02-17 |
| CVE-2017-12617 KEV EXP | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setti… | Patch first | 8.1 high | 100% | 2017-10-04 |
| CVE-2021-42013 KEV EXP | It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs… | Patch first | 9.8 critical | 100% | 2021-10-07 |
| CVE-2019-2725 KEV EXP | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected a… | Patch first | 9.8 critical | 100% | 2019-04-26 |
| CVE-2020-0688 KEV EXP | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microso… | Patch first | 8.8 high | 100% | 2020-02-11 |
| CVE-2021-3156 KEV EXP | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoe… | Patch first | 7.8 high | 100% | 2021-01-26 |
| CVE-2019-10149 KEV EXP | A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c m… | Patch first | 9.8 critical | 100% | 2019-06-05 |
| CVE-2018-2628 KEV EXP | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… | Patch first | 9.8 critical | 100% | 2018-04-19 |
| CVE-2022-1388 KEV EXP | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5,… | Patch first | 9.8 critical | 100% | 2022-05-05 |
| CVE-2018-15961 KEV EXP | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerab… | Patch first | 9.8 critical | 100% | 2018-09-25 |
| CVE-2018-10562 KEV EXP | An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponFor… | Patch first | 9.8 critical | 99.9% | 2018-05-04 |
| CVE-2017-11882 KEV EXP | Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an a… | Patch first | 7.8 high | 99.9% | 2017-11-15 |
| CVE-2015-3113 KEV EXP | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468… | Patch first | 9.8 critical | 99.9% | 2015-06-23 |
| CVE-2022-30525 KEV EXP | A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware ve… | Patch first | 9.8 critical | 99.9% | 2022-05-12 |
| CVE-2021-3129 KEV EXP | Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure us… | Patch first | 9.8 critical | 99.9% | 2021-01-12 |
| CVE-2020-10189 KEV EXP | Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the Fi… | Patch first | 9.8 critical | 99.9% | 2020-03-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt