peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

205,436 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-1003030 KEV EXP A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps… Patch first 9.9 critical 96.9% 2019-03-08
CVE-2011-3544 KEV EXP Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untruste… Patch first 9.8 critical 96.7% 2011-10-19
CVE-2020-11651 KEV EXP An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate… Patch first 9.8 critical 96.6% 2020-04-30
CVE-2009-1151 KEV EXP Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitra… Patch first 9.8 critical 96.6% 2009-03-26
CVE-2010-0840 KEV EXP Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 a… Patch first 9.8 critical 96.3% 2010-04-01
CVE-2018-14847 KEV EXP MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary f… Patch first 9.1 critical 96.1% 2018-08-02
CVE-2022-24112 KEV EXP An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (… Patch first 9.8 critical 96.1% 2022-02-11
CVE-2015-4852 KEV EXP The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands… Patch first 9.8 critical 96% 2015-11-18
CVE-2020-5847 KEV EXP Unraid through 6.8.0 allows Remote Code Execution. Patch first 9.8 critical 95.8% 2020-03-16
CVE-2015-0313 KEV EXP Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.4… Patch first 9.8 critical 95.3% 2015-02-02
CVE-2019-12989 KEV EXP Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. Patch first 9.8 critical 95% 2019-07-16
CVE-2018-14933 KEV EXP upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir co… Patch first 9.8 critical 94.9% 2018-08-04
CVE-2024-51378 KEV EXP getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and ex… Patch first 10.0 critical 94.7% 2024-10-29
CVE-2023-7028 KEV EXP An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior… Patch first 10.0 critical 94.6% 2024-01-12
CVE-2016-4117 KEV EXP Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2… Patch first 9.8 critical 94.4% 2016-05-11
CVE-2017-1000486 KEV EXP Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution Patch first 9.8 critical 94.1% 2018-01-03
CVE-2015-5122 KEV EXP Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Wi… Patch first 9.8 critical 94% 2015-07-14
CVE-2013-0625 KEV EXP Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbit… Patch first 9.8 critical 93.8% 2013-01-09
CVE-2012-1723 KEV EXP Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update… Patch first 9.8 critical 93.7% 2012-06-16
CVE-2013-0632 KEV EXP administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code b… Patch first 9.8 critical 93.6% 2013-01-17
CVE-2016-4437 KEV EXP Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code… Patch first 9.8 critical 93% 2016-06-07
CVE-2018-10561 KEV EXP An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device tha… Patch first 9.8 critical 92.9% 2018-05-04
CVE-2025-47812 KEV EXP In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user… Patch first 10.0 critical 92.9% 2025-07-10
CVE-2022-24706 KEV EXP In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.… Patch first 9.8 critical 92.5% 2022-04-26
CVE-2017-5689 KEV EXP An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and In… Patch first 9.8 critical 92.2% 2017-05-02
CVE-2020-8657 KEV EXP An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API ver… Patch first 9.8 critical 91.9% 2020-02-06
CVE-2025-64446 KEV EXP A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb… Patch first 9.8 critical 91.8% 2025-11-14
CVE-2024-5910 KEV EXP Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with ne… Patch first 9.8 critical 91.8% 2024-07-10
CVE-2018-11138 KEV EXP The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be ab… Patch first 9.8 critical 91.8% 2018-05-31
CVE-2012-5076 KEV EXP Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect c… Patch first 9.8 critical 91.3% 2012-10-16
← previous page 5 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt