CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,584 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
205,911 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-6209 EXP | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to ac… | Patch early | 10.0 critical | 17.2% | 2024-07-05 |
| CVE-2017-14244 EXP | An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access a… | Patch early | 9.8 critical | 17.1% | 2017-09-17 |
| CVE-2011-3829 EXP | ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, w… | Patch early | 4.0 medium | 17.1% | 2012-01-29 |
| CVE-2017-2361 EXP | An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer" component, which allows XSS… | Patch early | 6.1 medium | 17.1% | 2017-02-20 |
| CVE-2005-1191 EXP | The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in… | Patch early | 5.0 medium | 17.1% | 2005-05-02 |
| CVE-2006-3317 EXP | PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (… | Patch early | 5.1 medium | 17.1% | 2006-06-29 |
| CVE-2018-13981 EXP | The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default com… | Patch early | 9.8 critical | 17.1% | 2018-07-16 |
| CVE-2006-3354 EXP | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset Active… | Patch early | 5.0 medium | 17.1% | 2006-07-06 |
| CVE-2006-3910 EXP | Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefau… | Patch early | 5.0 medium | 17.1% | 2006-07-28 |
| CVE-2016-8581 EXP | A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker t… | Patch early | 6.1 medium | 17.1% | 2016-10-28 |
| CVE-2019-1912 EXP | A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to u… | Patch early | 9.1 critical | 17% | 2019-08-07 |
| CVE-2019-8641 EXP | An out-of-bounds read was addressed with improved input validation. | Patch early | 9.8 critical | 17% | 2019-12-18 |
| CVE-2002-1634 EXP | Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3)… | Patch early | 5.0 medium | 17% | 2002-12-31 |
| CVE-2019-11469 EXP | Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user c… | Patch early | 9.8 critical | 17% | 2019-04-23 |
| CVE-2017-1002008 EXP | Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-membe… | Patch early | 9.8 critical | 16.9% | 2017-09-14 |
| CVE-2015-3440 EXP | Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 16.9% | 2015-08-03 |
| CVE-2010-1345 EXP | Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary fil… | Patch early | 5.0 medium | 16.9% | 2010-04-09 |
| CVE-2014-2595 EXP | Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obt… | Patch early | 9.8 critical | 16.9% | 2020-02-12 |
| CVE-2014-0030 EXP | The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. | Patch early | 9.8 critical | 16.9% | 2017-10-10 |
| CVE-2006-3772 EXP | PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass security restrictions and obtain a… | Patch early | 5.1 medium | 16.8% | 2006-07-24 |
| CVE-2019-8042 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 16.8% | 2019-08-20 |
| CVE-2019-8197 EXP | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | Patch early | 9.8 critical | 16.8% | 2019-10-17 |
| CVE-2017-8535 EXP | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… | Patch early | 5.5 medium | 16.8% | 2017-05-26 |
| CVE-2017-8536 EXP | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… | Patch early | 5.5 medium | 16.8% | 2017-05-26 |
| CVE-2017-8537 EXP | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… | Patch early | 5.5 medium | 16.8% | 2017-05-26 |
| CVE-1999-0224 EXP | Denial of service in Windows NT messenger service through a long username. | Patch early | 5.0 medium | 16.8% | 1999-07-23 |
| CVE-2018-0494 EXP | GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line. | Patch early | 6.5 medium | 16.8% | 2018-05-06 |
| CVE-2008-2167 EXP | Cross-site scripting (XSS) vulnerability in ZyXEL ZyWALL 100 allows remote attackers to inject arbitrary web script or HTML via the Referer header, wh… | Patch early | 4.3 medium | 16.8% | 2008-05-13 |
| CVE-2018-15691 EXP | Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute a… | Patch early | 9.8 critical | 16.8% | 2018-08-30 |
| CVE-2018-9843 EXP | The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialize… | Patch early | 9.8 critical | 16.7% | 2018-04-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt