CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,648 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
205,551 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-2010 EXP | WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability | Patch early | 9.8 critical | 73.9% | 2020-02-12 |
| CVE-2013-1814 EXP | The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all… | Patch early | 4.0 medium | 73.8% | 2013-03-14 |
| CVE-2020-17456 EXP | SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page. | Patch early | 9.8 critical | 73.6% | 2020-08-20 |
| CVE-2015-8249 EXP | The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the… | Patch early | 9.8 critical | 73.6% | 2017-09-28 |
| CVE-2020-24881 EXP | SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. | Patch early | 9.8 critical | 73.4% | 2020-11-02 |
| CVE-2017-17560 EXP | An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php… | Patch early | 9.8 critical | 73.4% | 2017-12-12 |
| CVE-2020-11698 EXP | An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote at… | Patch early | 9.8 critical | 73.2% | 2020-09-17 |
| CVE-2017-11467 EXP | OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to exec… | Patch early | 9.8 critical | 73.1% | 2017-07-20 |
| CVE-2018-20526 EXP | Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php. | Patch early | 9.8 critical | 73.1% | 2019-03-21 |
| CVE-2005-2428 EXP | Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows… | Patch early | 5.0 medium | 73% | 2005-08-03 |
| CVE-2012-0394 EXP | The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands… | Patch early | 6.8 medium | 72.9% | 2012-01-08 |
| CVE-2021-24946 EXP | The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in th… | Patch early | 9.8 critical | 72.8% | 2021-12-13 |
| CVE-2017-6326 EXP | The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the abili… | Patch early | 10.0 critical | 72.8% | 2017-06-26 |
| CVE-2008-6505 EXP | Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary file… | Patch early | 5.0 medium | 72.7% | 2009-03-23 |
| CVE-2014-9618 EXP | The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authenticatio… | Patch early | 9.8 critical | 72.7% | 2017-09-19 |
| CVE-2021-4045 EXP | TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd bina… | Patch early | 9.8 critical | 72.4% | 2022-03-10 |
| CVE-2004-0751 EXP | The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a d… | Patch early | 5.0 medium | 72.3% | 2004-10-20 |
| CVE-2023-3460 EXP | The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allow… | Patch early | 9.8 critical | 72.3% | 2023-07-04 |
| CVE-2016-1560 EXP | ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support a… | Patch early | 9.8 critical | 72.3% | 2017-04-21 |
| CVE-2006-7196 EXP | Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through… | Patch early | 4.3 medium | 72.2% | 2007-05-10 |
| CVE-2019-16724 EXP | File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer… | Patch early | 9.8 critical | 72.2% | 2019-09-24 |
| CVE-2009-0478 EXP | Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an inv… | Patch early | 5.0 medium | 72% | 2009-02-08 |
| CVE-2021-40859 EXP | Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application f… | Patch early | 9.8 critical | 72% | 2021-12-07 |
| CVE-2010-2263 EXP | nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary… | Patch early | 5.0 medium | 71.9% | 2010-06-15 |
| CVE-2018-7251 EXP | An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL… | Patch early | 9.8 critical | 71.8% | 2018-02-19 |
| CVE-1999-1551 EXP | Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a lo… | Patch early | 5.0 medium | 71.8% | 1999-03-02 |
| CVE-2020-8518 EXP | Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution. | Patch early | 9.8 critical | 71.7% | 2020-02-17 |
| CVE-2014-8684 EXP | CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequen… | Patch early | 9.8 critical | 71.7% | 2017-09-19 |
| CVE-2021-39327 EXP | The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~… | Patch early | 5.3 medium | 71.7% | 2021-09-17 |
| CVE-2011-3011 EXP | BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently… | Patch early | 5.0 medium | 71.6% | 2011-08-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt