CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,672 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
318,025 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-0392 EXP | The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute ar… | Patch early | 6.8 medium | 97.5% | 2012-01-08 |
| CVE-2016-6601 EXP | Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrar… | Patch early | 7.5 high | 97.4% | 2017-01-23 |
| CVE-2025-4123 EXP | A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to r… | Patch early | 7.6 high | 97% | 2025-05-22 |
| CVE-2022-0824 EXP | Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990. | Patch early | 8.8 high | 97% | 2022-03-02 |
| CVE-2015-3306 EXP | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. | Patch early | 10.0 high | 96.8% | 2015-05-18 |
| CVE-2001-0500 EXP | Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to exec… | Patch early | 10.0 high | 96.7% | 2001-07-21 |
| CVE-2006-3747 EXP | Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, a… | Patch early | 7.6 high | 96.6% | 2006-07-28 |
| CVE-2012-2122 EXP | sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12,… | Patch early | 5.1 medium | 96.5% | 2012-06-26 |
| CVE-2017-6090 EXP | Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary… | Patch early | 8.8 high | 96.4% | 2017-10-03 |
| CVE-2024-10914 EXP | A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulner… | Patch early | 8.1 high | 96.3% | 2024-11-06 |
| CVE-2000-0573 EXP | The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitr… | Patch early | 10.0 high | 96.2% | 2000-07-07 |
| CVE-2018-19518 EXP | University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_r… | Patch early | 7.5 high | 96.1% | 2018-11-25 |
| CVE-1999-0016 EXP | Land IP denial of service. | Patch early | 5.0 medium | 95.7% | 1997-12-01 |
| CVE-2011-0049 EXP | Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read ar… | Patch early | 5.0 medium | 95.4% | 2011-02-04 |
| CVE-2019-20499 EXP | D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the W… | Patch early | 7.8 high | 95.3% | 2020-03-05 |
| CVE-2013-0333 EXP | lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data… | Patch early | 7.5 high | 95.3% | 2013-01-30 |
| CVE-2008-1447 EXP | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, a… | Patch early | 6.8 medium | 95.2% | 2008-07-08 |
| CVE-2006-3918 EXP | http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, an… | Patch early | 4.3 medium | 95.1% | 2006-07-28 |
| CVE-2002-0840 EXP | Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off"… | Patch early | 6.8 medium | 95.1% | 2002-10-11 |
| CVE-2017-9798 EXP | Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd… | Patch early | 7.5 high | 95% | 2017-09-18 |
| CVE-2011-4862 EXP | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, H… | Patch early | 10.0 high | 95% | 2011-12-25 |
| CVE-2002-0392 EXP | Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via… | Patch early | 7.5 high | 94.9% | 2002-07-03 |
| CVE-2015-5531 EXP | Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to sna… | Patch early | 5.0 medium | 94.8% | 2015-08-17 |
| CVE-2001-0797 EXP | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of argum… | Patch early | 10.0 high | 94.7% | 2001-12-12 |
| CVE-2013-2248 EXP | Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and condu… | Patch early | 5.8 medium | 94.7% | 2013-07-20 |
| CVE-2014-0515 EXP | Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on… | Patch early | 10.0 high | 94.6% | 2014-04-29 |
| CVE-2015-0235 EXP | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attac… | Patch early | 10.0 high | 94.6% | 2015-01-28 |
| CVE-2010-3972 EXP | Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Informati… | Patch early | 10.0 high | 94.5% | 2010-12-23 |
| CVE-2015-7857 EXP | SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5… | Patch early | 7.5 high | 94.5% | 2015-10-29 |
| CVE-2009-0580 EXP | Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enume… | Patch early | 4.3 medium | 94.4% | 2009-06-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt