CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,482 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,454 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-3066 KEV EXP | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulne… | Patch first | 9.8 critical | 90.6% | 2017-04-27 |
| CVE-2020-3952 KEV EXP | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not… | Patch first | 9.8 critical | 90.4% | 2020-04-10 |
| CVE-2013-0431 KEV EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted r… | Patch first | 5.3 medium | 90.2% | 2013-01-31 |
| CVE-2009-3960 KEV EXP | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex… | Patch first | 6.5 medium | 90.1% | 2010-02-15 |
| CVE-2011-2462 KEV EXP | Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.… | Patch first | 9.8 critical | 88.5% | 2011-12-07 |
| CVE-2020-8644 KEV EXP | PlaySMS before 1.4.3 does not sanitize inputs from a malicious string. | Patch first | 9.8 critical | 86.7% | 2020-02-05 |
| CVE-2019-4716 KEV EXP | IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and the… | Patch first | 9.8 critical | 86.4% | 2019-12-18 |
| CVE-2020-11652 KEV EXP | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some metho… | Patch first | 6.5 medium | 86.2% | 2020-04-30 |
| CVE-2015-0311 KEV EXP | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.20… | Patch first | 9.8 critical | 85.6% | 2015-01-23 |
| CVE-2025-57819 KEV EXP | FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-sup… | Patch first | 9.8 critical | 85.5% | 2025-08-28 |
| CVE-2020-11023 KEV EXP | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sani… | Patch first | 6.9 medium | 84.9% | 2020-04-29 |
| CVE-2020-5722 KEV EXP | The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker ca… | Patch first | 9.8 critical | 84.4% | 2020-03-23 |
| CVE-2017-11317 KEV EXP | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remo… | Patch first | 9.8 critical | 84.2% | 2017-08-23 |
| CVE-2020-3161 KEV EXP | A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a… | Patch first | 9.8 critical | 83.9% | 2020-04-15 |
| CVE-2016-10174 KEV EXP | The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffe… | Patch first | 9.8 critical | 83.3% | 2017-01-30 |
| CVE-2010-3765 KEV EXP | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10… | Patch first | 9.8 critical | 83.2% | 2010-10-28 |
| CVE-2015-1187 KEV EXP | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp. | Patch first | 9.8 critical | 82.9% | 2017-09-21 |
| CVE-2018-6789 KEV EXP | An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may ha… | Patch first | 9.8 critical | 82.1% | 2018-02-08 |
| CVE-2018-13382 KEV EXP | An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1… | Patch first | 9.1 critical | 81.7% | 2019-06-04 |
| CVE-2020-14871 KEV EXP | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 1… | Patch first | 10.0 critical | 80.2% | 2020-10-21 |
| CVE-2013-4810 KEV EXP | HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attack… | Patch first | 9.8 critical | 79.5% | 2013-09-16 |
| CVE-2010-0738 KEV EXP | The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 bef… | Patch first | 5.3 medium | 79.4% | 2010-04-28 |
| CVE-2013-3346 KEV EXP | Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of… | Patch first | 9.8 critical | 78.9% | 2013-08-30 |
| CVE-2017-11357 KEV EXP | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perf… | Patch first | 9.8 critical | 77.7% | 2017-08-23 |
| CVE-2016-3718 KEV EXP | The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (S… | Patch first | 5.5 medium | 76.7% | 2016-05-05 |
| CVE-2012-0391 KEV EXP | The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for… | Patch first | 9.8 critical | 75.6% | 2012-01-08 |
| CVE-2016-3715 KEV EXP | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. | Patch first | 5.5 medium | 75.3% | 2016-05-05 |
| CVE-2017-9248 KEV EXP | Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.… | Patch first | 9.8 critical | 75.1% | 2017-07-03 |
| CVE-2014-0780 KEV EXP | Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative password… | Patch first | 9.8 critical | 74.7% | 2014-04-25 |
| CVE-2005-2773 KEV EXP | HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node param… | Patch first | 9.8 critical | 74.6% | 2005-09-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt