CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,587 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
205,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-3153 EXP | Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attacke… | Patch early | 6.4 medium | 98.2% | 2012-10-16 |
| CVE-2020-35847 EXP | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function. | Patch early | 9.8 critical | 98.2% | 2020-12-30 |
| CVE-2014-5445 EXP | Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remot… | Patch early | 5.0 medium | 98% | 2014-12-04 |
| CVE-2023-6553 EXP | The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-… | Patch early | 9.8 critical | 97.8% | 2023-12-15 |
| CVE-2016-10045 EXP | The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arb… | Patch early | 9.8 critical | 97.7% | 2016-12-30 |
| CVE-2019-16662 EXP | An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php becau… | Patch early | 9.8 critical | 97.7% | 2019-10-28 |
| CVE-2018-11784 EXP | When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. r… | Patch early | 4.3 medium | 97.7% | 2018-10-04 |
| CVE-2019-18818 EXP | strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions… | Patch early | 9.8 critical | 97.6% | 2019-11-07 |
| CVE-2013-5211 EXP | The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via f… | Patch early | 5.0 medium | 97.5% | 2014-01-02 |
| CVE-2012-0392 EXP | The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute ar… | Patch early | 6.8 medium | 97.5% | 2012-01-08 |
| CVE-2021-3378 EXP | FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then… | Patch early | 9.8 critical | 97.5% | 2021-02-01 |
| CVE-2019-0230 EXP | Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. | Patch early | 9.8 critical | 97.4% | 2020-09-14 |
| CVE-2018-17456 EXP | Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code… | Patch early | 9.8 critical | 97.4% | 2018-10-06 |
| CVE-2017-3248 EXP | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affecte… | Patch early | 9.8 critical | 97.3% | 2017-01-27 |
| CVE-2018-9206 EXP | Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0 | Patch early | 9.8 critical | 97.3% | 2018-10-11 |
| CVE-2016-8869 EXP | The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers… | Patch early | 9.8 critical | 97.3% | 2016-11-04 |
| CVE-2020-11455 EXP | LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php. | Patch early | 9.8 critical | 97.2% | 2020-04-01 |
| CVE-2016-9299 EXP | The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java objec… | Patch early | 9.8 critical | 96.9% | 2017-01-12 |
| CVE-2021-44790 EXP | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd… | Patch early | 9.8 critical | 96.8% | 2021-12-20 |
| CVE-2019-17662 EXP | ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication i… | Patch early | 9.8 critical | 96.8% | 2019-10-16 |
| CVE-2019-9194 EXP | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. | Patch early | 9.8 critical | 96.7% | 2019-02-26 |
| CVE-2020-3187 EXP | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co… | Patch early | 9.1 critical | 96.6% | 2020-05-06 |
| CVE-2012-2122 EXP | sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12,… | Patch early | 5.1 medium | 96.5% | 2012-06-26 |
| CVE-2019-15975 EXP | Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker… | Patch early | 9.8 critical | 96.5% | 2020-01-06 |
| CVE-2011-2523 EXP | vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp. | Patch early | 9.8 critical | 96.2% | 2019-11-27 |
| CVE-2022-36446 EXP | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command. | Patch early | 9.8 critical | 96% | 2022-07-25 |
| CVE-2023-0297 EXP | Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31. | Patch early | 9.8 critical | 95.9% | 2023-01-14 |
| CVE-1999-0016 EXP | Land IP denial of service. | Patch early | 5.0 medium | 95.7% | 1997-12-01 |
| CVE-2019-1663 EXP | A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, a… | Patch early | 9.8 critical | 95.7% | 2019-02-28 |
| CVE-2020-11530 EXP | A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied… | Patch early | 9.8 critical | 95.7% | 2020-05-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt