CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,482 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,454 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-3043 KEV EXP | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to… | Patch first | 9.8 critical | 73.9% | 2015-04-14 |
| CVE-2024-37383 KEV EXP | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. | Patch first | 6.1 medium | 73.3% | 2024-06-07 |
| CVE-2017-6316 KEV EXP | Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On… | Patch first | 9.8 critical | 73% | 2017-07-20 |
| CVE-2019-9978 KEV EXP | The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as explo… | Patch first | 6.1 medium | 72.9% | 2019-03-24 |
| CVE-2018-7841 KEV EXP | A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper se… | Patch first | 9.8 critical | 72.7% | 2019-05-22 |
| CVE-2010-4344 KEV EXP | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMT… | Patch first | 9.8 critical | 71.7% | 2010-12-14 |
| CVE-2016-2386 KEV EXP | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspeci… | Patch first | 9.8 critical | 71.5% | 2016-02-16 |
| CVE-2017-6077 KEV EXP | ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metac… | Patch first | 9.8 critical | 68.7% | 2017-02-22 |
| CVE-2013-3896 KEV EXP | Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to… | Patch first | 5.5 medium | 68% | 2013-10-09 |
| CVE-2013-2729 KEV EXP | Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code… | Patch first | 9.8 critical | 66.6% | 2013-05-16 |
| CVE-2026-0770 KEV EXP | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote a… | Patch first | 9.8 critical | 63.8% | 2026-01-23 |
| CVE-2019-8394 KEV EXP | Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. | Patch first | 6.5 medium | 63.3% | 2019-02-17 |
| CVE-2017-0059 KEV EXP | Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Inter… | Patch first | 4.3 medium | 62% | 2017-03-17 |
| CVE-2019-5786 KEV EXP | Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access vi… | Patch first | 6.5 medium | 61.1% | 2019-06-27 |
| CVE-2025-32463 KEV EXP | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot op… | Patch first | 9.3 critical | 61% | 2025-06-30 |
| CVE-2018-7445 KEV EXP | A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the… | Patch first | 9.8 critical | 60.8% | 2018-03-19 |
| CVE-2025-24054 KEV EXP | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | Patch first | 6.5 medium | 58.9% | 2025-03-11 |
| CVE-2019-5825 KEV EXP | Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafte… | Patch first | 6.5 medium | 55.9% | 2019-11-25 |
| CVE-2019-11708 KEV EXP | Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent p… | Patch first | 10.0 critical | 55.9% | 2019-07-23 |
| CVE-2016-2388 KEV EXP | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP requ… | Patch first | 5.3 medium | 52.2% | 2016-02-16 |
| CVE-2013-5223 KEV EXP | Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web scr… | Patch first | 5.4 medium | 50.8% | 2013-11-19 |
| CVE-2026-39987 KEV EXP | marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks aut… | Patch first | 9.8 critical | 37.9% | 2026-04-09 |
| CVE-2018-13374 KEV EXP | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LD… | Patch first | 4.3 medium | 37.8% | 2019-01-22 |
| CVE-2016-4655 KEV EXP | The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app. | Patch first | 5.5 medium | 33.4% | 2016-08-25 |
| CVE-2026-56290 KEV EXP | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable… | Patch first | 9.8 critical | 30.9% | 2026-06-29 |
| CVE-2018-2380 KEV EXP | SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characte… | Patch first | 6.6 medium | 28.9% | 2018-03-01 |
| CVE-2026-9198 KEV EXP | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with… | Patch first | 9.8 critical | 28.7% | 2026-07-17 |
| CVE-2026-33017 KEV EXP | Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}… | Patch first | 9.8 critical | 24.8% | 2026-03-20 |
| CVE-2014-0196 KEV EXP | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST"… | Patch first | 5.5 medium | 22.5% | 2014-05-07 |
| CVE-2025-24085 KEV EXP | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15… | Patch first | 10.0 critical | 17.5% | 2025-01-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt