CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,436 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-26
317,842 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-1472 KEV EXP | An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, us… | Patch first | 5.5 medium | 99.4% | 2020-08-17 |
| CVE-2017-0148 KEV EXP | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Wind… | Patch first | 8.1 high | 99.4% | 2017-03-17 |
| CVE-2017-0144 KEV EXP | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Wind… | Patch first | 8.8 high | 99.2% | 2017-03-17 |
| CVE-2020-11978 KEV EXP | An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DA… | Patch first | 8.8 high | 99.2% | 2020-07-17 |
| CVE-2022-36804 KEV EXP | Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from vers… | Patch first | 8.8 high | 99.2% | 2022-08-25 |
| CVE-2020-10199 KEV EXP | Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). | Patch first | 8.8 high | 99.1% | 2020-04-01 |
| CVE-2020-0618 KEV EXP | A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL… | Patch first | 8.8 high | 99% | 2020-02-11 |
| CVE-2019-17558 KEV EXP | Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provid… | Patch first | 7.5 high | 98.6% | 2019-12-30 |
| CVE-2019-11539 KEV EXP | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Po… | Patch first | 7.2 high | 98.5% | 2019-04-26 |
| CVE-2024-20767 KEV EXP | ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system re… | Patch first | 7.4 high | 98.5% | 2024-03-18 |
| CVE-2019-5418 KEV EXP | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers… | Patch first | 7.5 high | 98.5% | 2019-03-27 |
| CVE-2008-2992 KEV EXP | Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls… | Patch first | 7.8 high | 98.5% | 2008-11-04 |
| CVE-2020-11738 KEV EXP | The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parame… | Patch first | 7.5 high | 97.8% | 2020-04-13 |
| CVE-2020-17519 KEV EXP | A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of th… | Patch first | 7.5 high | 97.8% | 2021-01-05 |
| CVE-2022-43769 KEV EXP | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property va… | Patch first | 8.8 high | 97.7% | 2023-04-03 |
| CVE-2016-3714 KEV EXP | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1… | Patch first | 8.4 high | 97.5% | 2016-05-05 |
| CVE-2019-9082 KEV EXP | ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefun… | Patch first | 8.8 high | 97.4% | 2019-02-24 |
| CVE-2023-27524 KEV EXP | Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KE… | Patch first | 8.9 high | 97.4% | 2023-04-24 |
| CVE-2020-14864 KEV EXP | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions… | Patch first | 7.5 high | 97.2% | 2020-10-21 |
| CVE-2019-20500 KEV EXP | D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web… | Patch first | 7.8 high | 97.1% | 2020-03-05 |
| CVE-2015-2051 KEV EXP | The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDevi… | Patch first | 8.8 high | 97.1% | 2015-02-23 |
| CVE-2017-8291 KEV EXP | Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" s… | Patch first | 7.8 high | 97% | 2017-04-27 |
| CVE-2019-3398 KEV EXP | Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to a… | Patch first | 8.8 high | 96.8% | 2019-04-18 |
| CVE-2010-3962 KEV EXP | Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Casca… | Patch first | 8.1 high | 96.8% | 2010-11-05 |
| CVE-2009-0927 KEV EXP | Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arb… | Patch first | 8.8 high | 96.6% | 2009-03-19 |
| CVE-2017-17562 KEV EXP | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializin… | Patch first | 8.1 high | 96.3% | 2017-12-12 |
| CVE-2019-20085 KEV EXP | TVT NVMS-1000 devices allow GET /.. Directory Traversal | Patch first | 7.5 high | 96.1% | 2019-12-30 |
| CVE-2018-20250 KEV EXP | In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.d… | Patch first | 7.8 high | 96% | 2019-02-05 |
| CVE-2019-1652 KEV EXP | A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticate… | Patch first | 7.2 high | 95.9% | 2019-01-24 |
| CVE-2016-0752 KEV EXP | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x befo… | Patch first | 7.5 high | 95.5% | 2016-02-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt