CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,436 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-26
398,436 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-11043 KEV EXP | In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM modul… | Patch first | 8.7 high | 99.8% | 2019-10-28 |
| CVE-2020-13927 KEV EXP | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to use… | Patch first | 9.8 critical | 99.8% | 2020-11-10 |
| CVE-2025-25257 KEV EXP | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.… | Patch first | 9.8 critical | 99.8% | 2025-07-17 |
| CVE-2019-18935 KEV EXP | Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploit… | Patch first | 9.8 critical | 99.7% | 2019-12-11 |
| CVE-2021-22205 KEV EXP | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passe… | Patch first | 10.0 critical | 99.7% | 2021-04-23 |
| CVE-2019-16759 KEV EXP | vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. | Patch first | 9.8 critical | 99.7% | 2019-09-24 |
| CVE-2010-2861 KEV EXP | Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitra… | Patch first | 9.8 critical | 99.7% | 2010-08-11 |
| CVE-2016-10033 KEV EXP | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and… | Patch first | 9.8 critical | 99.7% | 2016-12-30 |
| CVE-2019-15107 KEV EXP | An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability. | Patch first | 9.8 critical | 99.7% | 2019-08-16 |
| CVE-2017-0147 KEV EXP | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Wind… | Patch first | 7.5 high | 99.7% | 2017-03-17 |
| CVE-2017-1000353 KEV EXP | Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated rem… | Patch first | 9.8 critical | 99.7% | 2018-01-29 |
| CVE-2017-12615 KEV EXP | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to… | Patch first | 8.1 high | 99.6% | 2017-09-19 |
| CVE-2024-28995 KEV EXP | SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. | Patch first | 8.6 high | 99.6% | 2024-06-06 |
| CVE-2014-6278 KEV EXP | GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to… | Patch first | 8.8 high | 99.6% | 2014-09-30 |
| CVE-2018-20062 KEV EXP | An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the f… | Patch first | 9.8 critical | 99.5% | 2018-12-11 |
| CVE-2017-0199 KEV EXP | Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 20… | Patch first | 7.8 high | 99.5% | 2017-04-12 |
| CVE-2024-23692 KEV EXP | Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, u… | Patch first | 9.8 critical | 99.5% | 2024-05-31 |
| CVE-2018-0171 KEV EXP | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigge… | Patch first | 9.8 critical | 99.5% | 2018-03-28 |
| CVE-2017-7494 KEV EXP | Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upl… | Patch first | 9.8 critical | 99.4% | 2017-05-30 |
| CVE-2011-0611 KEV EXP | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and… | Patch first | 8.8 high | 99.4% | 2011-04-13 |
| CVE-2017-9805 KEV EXP | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for dese… | Patch first | 8.1 high | 99.4% | 2017-09-15 |
| CVE-2020-1472 KEV EXP | An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, us… | Patch first | 5.5 medium | 99.4% | 2020-08-17 |
| CVE-2017-0148 KEV EXP | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Wind… | Patch first | 8.1 high | 99.4% | 2017-03-17 |
| CVE-2015-5119 KEV EXP | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x… | Patch first | 9.8 critical | 99.3% | 2015-07-08 |
| CVE-2014-6287 KEV EXP | The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to exec… | Patch first | 9.8 critical | 99.3% | 2014-10-07 |
| CVE-2020-1938 KEV EXP | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as h… | Patch first | 9.8 critical | 99.3% | 2020-02-24 |
| CVE-2017-0144 KEV EXP | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Wind… | Patch first | 8.8 high | 99.2% | 2017-03-17 |
| CVE-2020-0646 KEV EXP | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execu… | Patch first | 9.8 critical | 99.2% | 2020-01-14 |
| CVE-2024-27348 KEV EXP | RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & J… | Patch first | 9.8 critical | 99.2% | 2024-04-22 |
| CVE-2018-7602 KEV EXP | A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple a… | Patch first | 9.8 critical | 99.2% | 2018-07-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt