CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,648 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
205,537 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-0847 EXP | The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted director… | Patch early | 9.8 critical | 75.7% | 2004-11-03 |
| CVE-2022-1162 EXP | A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7… | Patch early | 9.1 critical | 75.6% | 2022-04-04 |
| CVE-2018-9160 EXP | SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses. | Patch early | 9.8 critical | 75.6% | 2018-03-31 |
| CVE-2022-32429 EXP | An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 all… | Patch early | 9.8 critical | 75.6% | 2022-08-10 |
| CVE-2004-2086 EXP | Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (c… | Patch early | 5.0 medium | 75.5% | 2004-02-06 |
| CVE-2019-12255 EXP | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that lead… | Patch early | 9.8 critical | 75.3% | 2019-08-09 |
| CVE-2001-0925 EXP | The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP requ… | Patch early | 5.0 medium | 75.2% | 2001-03-12 |
| CVE-2022-23178 EXP | An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthent… | Patch early | 9.8 critical | 75.2% | 2022-01-15 |
| CVE-2015-2794 EXP | The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct r… | Patch early | 9.8 critical | 75.1% | 2017-02-06 |
| CVE-2019-20215 EXP | D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi()… | Patch early | 9.8 critical | 75.1% | 2020-01-29 |
| CVE-2013-0803 EXP | A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code. | Patch early | 9.8 critical | 75% | 2020-02-11 |
| CVE-2014-4977 EXP | Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the… | Patch early | 6.5 medium | 74.9% | 2014-07-16 |
| CVE-2018-16167 EXP | LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. | Patch early | 9.8 critical | 74.9% | 2019-01-09 |
| CVE-2025-30208 EXP | Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies acce… | Patch early | 5.3 medium | 74.8% | 2025-03-24 |
| CVE-2018-17128 EXP | A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode. | Patch early | 5.4 medium | 74.8% | 2018-09-17 |
| CVE-2004-2466 EXP | chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a… | Patch early | 5.0 medium | 74.7% | 2004-12-31 |
| CVE-2004-1060 EXP | Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network t… | Patch early | 5.0 medium | 74.7% | 2004-04-12 |
| CVE-2023-6019 EXP | A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remot… | Patch early | 9.8 critical | 74.6% | 2023-11-16 |
| CVE-2020-35848 EXP | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function. | Patch early | 9.8 critical | 74.6% | 2020-12-30 |
| CVE-2017-8046 EXP | Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spri… | Patch early | 9.8 critical | 74.5% | 2018-01-04 |
| CVE-2013-7390 EXP | Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attacker… | Patch early | 9.8 critical | 74.5% | 2020-01-27 |
| CVE-2023-5222 EXP | A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the f… | Patch early | 6.3 medium | 74.5% | 2023-09-27 |
| CVE-1999-0128 EXP | Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. | Patch early | 5.0 medium | 74.5% | 1996-12-18 |
| CVE-2013-3336 EXP | Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors. | Patch early | 5.0 medium | 74.3% | 2013-05-09 |
| CVE-2016-1287 EXP | Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before… | Patch early | 9.8 critical | 74.2% | 2016-02-11 |
| CVE-2005-2297 EXP | Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a la… | Patch early | 4.6 medium | 74.2% | 2005-07-19 |
| CVE-2017-5715 EXP | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an att… | Patch early | 5.6 medium | 74% | 2018-01-04 |
| CVE-2015-9266 EXP | The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to u… | Patch early | 9.8 critical | 74% | 2018-09-05 |
| CVE-2019-10098 EXP | In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newl… | Patch early | 6.1 medium | 74% | 2019-09-25 |
| CVE-2011-0762 EXP | The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption… | Patch early | 4.0 medium | 73.9% | 2011-03-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt