CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,105 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
185,540 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-16666 EXP | Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file. NO… | Patch early | 8.8 high | 80.8% | 2018-01-05 |
| CVE-2010-3552 EXP | Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect conf… | Patch early | 10.0 high | 80.7% | 2010-10-19 |
| CVE-2016-6433 EXP | The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands… | Patch early | 8.8 high | 80.7% | 2016-10-06 |
| CVE-2019-10669 EXP | An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where use… | Patch early | 7.2 high | 80.7% | 2019-09-09 |
| CVE-2014-9195 EXP | Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-complia… | Patch early | 10.0 high | 80.7% | 2015-01-17 |
| CVE-2018-12464 EXP | A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated re… | Patch early | 10.0 critical | 80.7% | 2018-06-29 |
| CVE-2015-7766 EXP | PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a commen… | Patch early | 9.0 high | 80.6% | 2015-10-09 |
| CVE-2024-20419 EXP | A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to… | Patch early | 10.0 critical | 80.6% | 2024-07-17 |
| CVE-2015-7808 EXP | The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and… | Patch early | 7.5 high | 80.6% | 2015-11-24 |
| CVE-2021-21425 EXP | Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an unau… | Patch early | 9.3 critical | 80.6% | 2021-04-07 |
| CVE-2011-5034 EXP | Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, whi… | Patch early | 7.8 high | 80.6% | 2011-12-30 |
| CVE-2020-13160 EXP | AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution. | Patch early | 9.8 critical | 80.6% | 2020-06-09 |
| CVE-2010-0805 EXP | The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers… | Patch early | 9.3 high | 80.5% | 2010-03-31 |
| CVE-2008-4397 EXP | Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 a… | Patch early | 10.0 high | 80.5% | 2008-10-14 |
| CVE-2009-1185 EXP | udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NET… | Patch early | 7.2 high | 80.4% | 2009-04-17 |
| CVE-2010-0361 EXP | Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to… | Patch early | 10.0 high | 80.4% | 2010-01-20 |
| CVE-2008-0244 EXP | SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo a… | Patch early | 10.0 high | 80.3% | 2008-01-12 |
| CVE-2003-0349 EXP | Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Ser… | Patch early | 7.5 high | 80.3% | 2003-07-24 |
| CVE-2007-5365 EXP | Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based… | Patch early | 7.2 high | 80.3% | 2007-10-11 |
| CVE-2014-3829 EXP | displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitra… | Patch early | 10.0 high | 80.2% | 2014-10-23 |
| CVE-2014-9583 EXP | common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other router… | Patch early | 10.0 high | 80.2% | 2015-01-08 |
| CVE-2002-1359 EXP | Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service… | Patch early | 10.0 high | 80.2% | 2002-12-23 |
| CVE-2015-7387 EXP | ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL com… | Patch early | 7.5 high | 80.2% | 2015-09-28 |
| CVE-2019-0567 EXP | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scri… | Patch early | 7.5 high | 80.1% | 2019-01-08 |
| CVE-2018-12465 EXP | An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authe… | Patch early | 9.1 critical | 80% | 2018-06-29 |
| CVE-2013-5743 EXP | Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7. | Patch early | 9.8 critical | 80% | 2019-12-11 |
| CVE-2019-11600 EXP | A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id… | Patch early | 8.1 high | 80% | 2019-05-13 |
| CVE-2019-4279 EXP | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence o… | Patch early | 9.8 critical | 79.9% | 2019-05-17 |
| CVE-2013-6829 EXP | admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parame… | Patch early | 7.5 high | 79.9% | 2013-11-20 |
| CVE-2021-42362 EXP | The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src… | Patch early | 8.8 high | 79.8% | 2021-11-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt