CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,482 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
185,349 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-14933 KEV EXP | upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir co… | Patch first | 9.8 critical | 94.9% | 2018-08-04 |
| CVE-2017-9822 KEV EXP | DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." | Patch first | 8.8 high | 94.8% | 2017-07-20 |
| CVE-2024-51378 KEV EXP | getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and ex… | Patch first | 10.0 critical | 94.7% | 2024-10-29 |
| CVE-2023-7028 KEV EXP | An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior… | Patch first | 10.0 critical | 94.6% | 2024-01-12 |
| CVE-2016-4117 KEV EXP | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2… | Patch first | 9.8 critical | 94.4% | 2016-05-11 |
| CVE-2021-4034 KEV EXP | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivilege… | Patch first | 7.8 high | 94.3% | 2022-01-28 |
| CVE-2017-1000486 KEV EXP | Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution | Patch first | 9.8 critical | 94.1% | 2018-01-03 |
| CVE-2016-0189 KEV EXP | The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attacke… | Patch first | 7.5 high | 94.1% | 2016-05-11 |
| CVE-2015-5122 KEV EXP | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Wi… | Patch first | 9.8 critical | 94% | 2015-07-14 |
| CVE-2020-1147 KEV EXP | A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source ma… | Patch first | 7.8 high | 94% | 2020-07-14 |
| CVE-2013-0625 KEV EXP | Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbit… | Patch first | 9.8 critical | 93.8% | 2013-01-09 |
| CVE-2012-1723 KEV EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update… | Patch first | 9.8 critical | 93.7% | 2012-06-16 |
| CVE-2013-0632 KEV EXP | administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code b… | Patch first | 9.8 critical | 93.6% | 2013-01-17 |
| CVE-2017-0143 KEV EXP | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Wind… | Patch first | 8.8 high | 93.3% | 2017-03-17 |
| CVE-2020-5849 KEV EXP | Unraid 6.8.0 allows authentication bypass. | Patch first | 7.5 high | 93.2% | 2020-03-16 |
| CVE-2016-4437 KEV EXP | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code… | Patch first | 9.8 critical | 93% | 2016-06-07 |
| CVE-2018-10561 KEV EXP | An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device tha… | Patch first | 9.8 critical | 92.9% | 2018-05-04 |
| CVE-2025-47812 KEV EXP | In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user… | Patch first | 10.0 critical | 92.9% | 2025-07-10 |
| CVE-2022-0847 KEV EXP | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_p… | Patch first | 7.8 high | 92.8% | 2022-03-10 |
| CVE-2022-24706 KEV EXP | In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.… | Patch first | 9.8 critical | 92.5% | 2022-04-26 |
| CVE-2022-43939 KEV EXP | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonic… | Patch first | 8.6 high | 92.3% | 2023-04-03 |
| CVE-2017-5689 KEV EXP | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and In… | Patch first | 9.8 critical | 92.2% | 2017-05-02 |
| CVE-2019-2616 KEV EXP | Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported vers… | Patch first | 7.2 high | 92.2% | 2019-04-23 |
| CVE-2019-6340 KEV EXP | Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to ar… | Patch first | 8.1 high | 92% | 2019-02-21 |
| CVE-2010-0249 KEV EXP | Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; W… | Patch first | 8.8 high | 91.9% | 2010-01-15 |
| CVE-2020-8657 KEV EXP | An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API ver… | Patch first | 9.8 critical | 91.9% | 2020-02-06 |
| CVE-2025-64446 KEV EXP | A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb… | Patch first | 9.8 critical | 91.8% | 2025-11-14 |
| CVE-2024-5910 KEV EXP | Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with ne… | Patch first | 9.8 critical | 91.8% | 2024-07-10 |
| CVE-2018-11138 KEV EXP | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be ab… | Patch first | 9.8 critical | 91.8% | 2018-05-31 |
| CVE-2010-2568 KEV EXP | Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote atta… | Patch first | 7.8 high | 91.3% | 2010-07-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt