CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,041 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
403,041 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-6435 EXP | cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers… | Patch early | 7.5 high | 12.6% | 2018-01-12 |
| CVE-2004-1491 EXP | Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or lau… | Patch early | 5.0 medium | 12.6% | 2004-12-31 |
| CVE-1999-1063 EXP | CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter. | Patch early | 10.0 high | 12.6% | 1999-06-01 |
| CVE-2018-19861 EXP | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is… | Patch early | 9.8 critical | 12.6% | 2019-01-03 |
| CVE-2018-19862 EXP | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is… | Patch early | 9.8 critical | 12.6% | 2019-01-03 |
| CVE-2011-0489 EXP | The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows remote attackers to modify data,… | Patch early | 7.5 high | 12.6% | 2011-01-18 |
| CVE-2018-8898 EXP | A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer=… | Patch early | 9.8 critical | 12.5% | 2018-05-23 |
| CVE-2018-10285 EXP | The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attack… | Patch early | 9.8 critical | 12.5% | 2018-04-22 |
| CVE-2019-6272 EXP | Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code. | Patch early | 8.8 high | 12.5% | 2019-03-21 |
| CVE-2019-6275 EXP | Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code… | Patch early | 8.8 high | 12.5% | 2019-03-21 |
| CVE-2001-0561 EXP | Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack… | Patch early | 7.5 high | 12.5% | 2001-08-14 |
| CVE-2012-5672 EXP | Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read a… | Patch early | 4.3 medium | 12.5% | 2012-10-25 |
| CVE-2015-5354 EXP | Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks v… | Patch early | 5.8 medium | 12.5% | 2015-07-01 |
| CVE-2014-8675 EXP | Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain… | Patch early | 7.5 high | 12.5% | 2017-08-31 |
| CVE-2007-0981 EXP | Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the sam… | Patch early | 7.5 high | 12.5% | 2007-02-16 |
| CVE-2019-19774 EXP | An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /e… | Patch early | 8.8 high | 12.5% | 2019-12-13 |
| CVE-2017-5630 EXP | PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which all… | Patch early | 7.5 high | 12.5% | 2017-02-01 |
| CVE-2012-4528 EXP | The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP app… | Patch early | 5.0 medium | 12.5% | 2012-12-28 |
| CVE-2017-17976 EXP | In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. | Patch early | 9.8 critical | 12.5% | 2018-01-26 |
| CVE-2010-3124 EXP | Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possibly remote attackers, to execut… | Patch early | 9.3 high | 12.5% | 2010-08-26 |
| CVE-2018-10070 EXP | A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sendin… | Patch early | 7.5 high | 12.5% | 2018-04-16 |
| CVE-2008-1193 EXP | Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier,… | Patch early | 9.3 high | 12.5% | 2008-03-06 |
| CVE-2010-0013 EXP | Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arb… | Patch early | 7.5 high | 12.5% | 2010-01-09 |
| CVE-2014-5246 EXP | The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access… | Patch early | 10.0 high | 12.5% | 2014-08-22 |
| CVE-2008-2321 EXP | Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of… | Patch early | 9.3 high | 12.5% | 2008-08-04 |
| CVE-2006-0306 EXP | The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Back… | Patch early | 5.0 medium | 12.5% | 2006-01-19 |
| CVE-2018-10824 EXP | An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-… | Patch early | 9.8 critical | 12.5% | 2018-10-17 |
| CVE-2017-14095 EXP | A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution… | Patch early | 8.1 high | 12.5% | 2018-01-19 |
| CVE-2022-28213 EXP | When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the X… | Patch early | 8.1 high | 12.5% | 2022-04-12 |
| CVE-2016-7065 EXP | The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and poss… | Patch early | 8.8 high | 12.5% | 2016-10-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt