CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,483 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
169,001 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2000-0778 EXP | IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "… | Patch early | 5.0 medium | 87.3% | 2000-10-20 |
| CVE-2019-11358 EXP | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollutio… | Patch early | 6.1 medium | 87.2% | 2019-04-20 |
| CVE-2003-0132 EXP | A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed char… | Patch early | 5.0 medium | 86.7% | 2003-04-11 |
| CVE-2013-7091 EXP | Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows rem… | Patch early | 5.0 medium | 86.3% | 2013-12-13 |
| CVE-2014-0226 EXP | Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffe… | Patch early | 6.8 medium | 85.7% | 2014-07-20 |
| CVE-2011-0063 EXP | The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and… | Patch early | 5.0 medium | 85.5% | 2011-03-15 |
| CVE-2019-3799 EXP | Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions a… | Patch early | 6.5 medium | 85.3% | 2019-05-06 |
| CVE-2006-4847 EXP | Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC,… | Patch early | 6.5 medium | 85.3% | 2006-09-19 |
| CVE-2009-2335 EXP | WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allo… | Patch early | 5.0 medium | 85% | 2009-07-10 |
| CVE-2004-0493 EXP | The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an… | Patch early | 6.4 medium | 84.8% | 2004-08-06 |
| CVE-2019-8449 EXP | The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosur… | Patch early | 5.3 medium | 84.8% | 2019-09-11 |
| CVE-2007-3925 EXP | Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute a… | Patch early | 6.5 medium | 84.7% | 2007-07-21 |
| CVE-2015-1830 EXP | Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows a… | Patch early | 5.0 medium | 84.4% | 2015-08-19 |
| CVE-2012-4940 EXP | Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbit… | Patch early | 6.4 medium | 83.6% | 2012-10-31 |
| CVE-2023-22232 EXP | Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Secu… | Patch early | 5.3 medium | 83.4% | 2023-02-17 |
| CVE-2009-3733 EXP | Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMw… | Patch early | 5.0 medium | 83.4% | 2009-11-02 |
| CVE-2011-4885 EXP | PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote… | Patch early | 5.0 medium | 83.4% | 2011-12-30 |
| CVE-2019-14470 EXP | cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php… | Patch early | 6.1 medium | 83% | 2019-09-04 |
| CVE-2005-0356 EXP | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to caus… | Patch early | 5.0 medium | 82.8% | 2005-05-31 |
| CVE-2020-2230 EXP | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting… | Patch early | 5.4 medium | 82.7% | 2020-08-12 |
| CVE-2014-9034 EXP | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause… | Patch early | 5.0 medium | 82.7% | 2014-11-25 |
| CVE-2006-0003 EXP | Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Acc… | Patch early | 5.1 medium | 82.5% | 2006-04-12 |
| CVE-2021-28164 EXP | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to ac… | Patch early | 5.3 medium | 82.4% | 2021-04-01 |
| CVE-2009-2521 EXP | Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users… | Patch early | 5.0 medium | 82.3% | 2009-09-04 |
| CVE-2014-9016 EXP | The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote… | Patch early | 5.0 medium | 82.2% | 2014-11-24 |
| CVE-2012-0053 EXP | protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) e… | Patch early | 4.3 medium | 82.2% | 2012-01-28 |
| CVE-2017-0038 EXP | gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S… | Patch early | 5.5 medium | 82.1% | 2017-02-20 |
| CVE-2019-10092 EXP | In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the… | Patch early | 6.1 medium | 81.5% | 2019-09-26 |
| CVE-2013-4212 EXP | Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via… | Patch early | 6.8 medium | 81.1% | 2013-12-07 |
| CVE-2007-6203 EXP | Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request… | Patch early | 4.3 medium | 80.7% | 2007-12-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt