CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,612 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
205,518 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-25148 EXP | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter f… | Patch early | 9.8 critical | 80.9% | 2022-02-24 |
| CVE-2007-6203 EXP | Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request… | Patch early | 4.3 medium | 80.7% | 2007-12-03 |
| CVE-2018-12464 EXP | A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated re… | Patch early | 10.0 critical | 80.7% | 2018-06-29 |
| CVE-2024-20419 EXP | A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to… | Patch early | 10.0 critical | 80.6% | 2024-07-17 |
| CVE-2021-21425 EXP | Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an unau… | Patch early | 9.3 critical | 80.6% | 2021-04-07 |
| CVE-2020-13160 EXP | AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution. | Patch early | 9.8 critical | 80.6% | 2020-06-09 |
| CVE-2013-4123 EXP | client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port num… | Patch early | 5.0 medium | 80.5% | 2013-09-16 |
| CVE-2004-0230 EXP | TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to… | Patch early | 5.0 medium | 80.3% | 2004-08-18 |
| CVE-2009-1386 EXP | ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS Chan… | Patch early | 5.0 medium | 80.1% | 2009-06-04 |
| CVE-2004-0790 EXP | Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages,… | Patch early | 5.0 medium | 80.1% | 2005-04-12 |
| CVE-2018-12465 EXP | An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authe… | Patch early | 9.1 critical | 80% | 2018-06-29 |
| CVE-2013-5743 EXP | Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7. | Patch early | 9.8 critical | 80% | 2019-12-11 |
| CVE-2000-0246 EXP | IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to… | Patch early | 5.0 medium | 80% | 2000-03-30 |
| CVE-2016-0491 EXP | Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows rem… | Patch early | 6.4 medium | 79.9% | 2016-01-21 |
| CVE-2019-4279 EXP | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence o… | Patch early | 9.8 critical | 79.9% | 2019-05-17 |
| CVE-2017-12557 EXP | A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. | Patch early | 9.8 critical | 79.8% | 2018-02-15 |
| CVE-2012-1495 EXP | install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter. | Patch early | 9.8 critical | 79.8% | 2020-01-27 |
| CVE-2016-6563 EXP | Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnera… | Patch early | 9.8 critical | 79.7% | 2018-07-13 |
| CVE-2011-4858 EXP | Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trig… | Patch early | 5.0 medium | 79.7% | 2012-01-05 |
| CVE-2016-2555 EXP | SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the sea… | Patch early | 9.8 critical | 79.6% | 2017-04-13 |
| CVE-2018-10662 EXP | An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. | Patch early | 9.8 critical | 79.5% | 2018-06-26 |
| CVE-2023-2745 EXP | WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated at… | Patch early | 5.4 medium | 79.5% | 2023-05-17 |
| CVE-2014-6034 EXP | Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8… | Patch early | 5.0 medium | 79% | 2014-12-04 |
| CVE-2019-1622 EXP | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to r… | Patch early | 5.3 medium | 78.9% | 2019-06-27 |
| CVE-2018-7890 EXP | A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredenti… | Patch early | 9.8 critical | 78.8% | 2018-03-08 |
| CVE-2021-24931 EXP | The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_exp… | Patch early | 9.8 critical | 78.8% | 2021-12-06 |
| CVE-2024-42327 EXP | A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerabilit… | Patch early | 9.9 critical | 78.7% | 2024-11-27 |
| CVE-2019-15954 EXP | An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on th… | Patch early | 9.9 critical | 78.7% | 2019-09-05 |
| CVE-2000-0302 EXP | Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument t… | Patch early | 5.0 medium | 78.6% | 2000-03-31 |
| CVE-2020-35665 EXP | An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include… | Patch early | 9.8 critical | 78.5% | 2020-12-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt