CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,436 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-26
36,450 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-7247 KEV EXP | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as… | Patch first | 9.8 critical | 99% | 2020-01-29 |
| CVE-2019-3929 KEV EXP | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W befor… | Patch first | 9.8 critical | 99% | 2019-04-30 |
| CVE-2017-3881 KEV EXP | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated,… | Patch first | 9.8 critical | 99% | 2017-03-17 |
| CVE-2017-9791 KEV EXP | The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the Acti… | Patch first | 9.8 critical | 98.9% | 2017-07-10 |
| CVE-2025-49113 KEV EXP | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is no… | Patch first | 9.9 critical | 98.9% | 2025-06-02 |
| CVE-2013-2465 KEV EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0… | Patch first | 9.8 critical | 98.8% | 2013-06-18 |
| CVE-2012-3152 KEV EXP | Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attacke… | Patch first | 9.1 critical | 98.8% | 2012-10-16 |
| CVE-2008-4250 KEV EXP | The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remo… | Patch first | 9.8 critical | 98.8% | 2008-10-23 |
| CVE-2012-4681 KEV EXP | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute ar… | Patch first | 9.8 critical | 98.5% | 2012-08-28 |
| CVE-2026-41940 KEV EXP | cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to g… | Patch first | 9.8 critical | 98.5% | 2026-04-29 |
| CVE-2016-3088 KEV EXP | The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT foll… | Patch first | 9.8 critical | 98.5% | 2016-06-01 |
| CVE-2017-15944 KEV EXP | Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary… | Patch first | 9.8 critical | 98.3% | 2017-12-11 |
| CVE-2016-1555 KEV EXP | (1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802T… | Patch first | 9.8 critical | 98.3% | 2017-04-21 |
| CVE-2022-22947 KEV EXP | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoin… | Patch first | 10.0 critical | 98.3% | 2022-03-03 |
| CVE-2012-0507 KEV EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 U… | Patch first | 9.8 critical | 98.1% | 2012-06-07 |
| CVE-2022-29303 KEV EXP | SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php. | Patch first | 9.8 critical | 98% | 2022-05-12 |
| CVE-2022-22536 KEV EXP | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulner… | Patch first | 10.0 critical | 97.9% | 2022-02-09 |
| CVE-2015-7450 KEV EXP | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote a… | Patch first | 9.8 critical | 97.8% | 2016-01-02 |
| CVE-2024-4358 KEV EXP | In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Ser… | Patch first | 9.8 critical | 97.5% | 2024-05-29 |
| CVE-2007-3010 KEV EXP | masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbit… | Patch first | 9.8 critical | 97.4% | 2007-09-18 |
| CVE-2020-25213 KEV EXP | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames… | Patch first | 10.0 critical | 97.3% | 2020-09-09 |
| CVE-2020-2555 KEV EXP | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affe… | Patch first | 9.8 critical | 97.1% | 2020-01-15 |
| CVE-2019-7256 KEV EXP | Linear eMerge E3-Series devices allow Command Injections. | Patch first | 9.8 critical | 97.1% | 2019-07-02 |
| CVE-2013-0422 KEV EXP | Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiat… | Patch first | 9.8 critical | 97% | 2013-01-10 |
| CVE-2019-1003030 KEV EXP | A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps… | Patch first | 9.9 critical | 96.9% | 2019-03-08 |
| CVE-2011-3544 KEV EXP | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untruste… | Patch first | 9.8 critical | 96.7% | 2011-10-19 |
| CVE-2020-11651 KEV EXP | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate… | Patch first | 9.8 critical | 96.6% | 2020-04-30 |
| CVE-2009-1151 KEV EXP | Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitra… | Patch first | 9.8 critical | 96.6% | 2009-03-26 |
| CVE-2010-0840 KEV EXP | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 a… | Patch first | 9.8 critical | 96.3% | 2010-04-01 |
| CVE-2018-14847 KEV EXP | MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary f… | Patch first | 9.1 critical | 96.1% | 2018-08-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt