CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-24499 EXP | The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks,… | Patch early | 9.8 critical | 60.1% | 2021-08-09 |
| CVE-2012-2576 EXP | SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWi… | Patch early | 9.8 critical | 59.4% | 2017-12-20 |
| CVE-2019-5485 EXP | NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository na… | Patch early | 10.0 critical | 58.8% | 2019-09-13 |
| CVE-2019-14931 EXP | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote… | Patch early | 9.8 critical | 58.1% | 2019-10-28 |
| CVE-2008-0081 EXP | Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to… | Patch early | 9.8 critical | 57.9% | 2008-01-16 |
| CVE-2018-7314 EXP | SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. | Patch early | 9.8 critical | 57.8% | 2018-02-22 |
| CVE-2018-6605 EXP | SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHov… | Patch early | 9.8 critical | 57.7% | 2018-02-05 |
| CVE-2016-8582 EXP | A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve da… | Patch early | 9.8 critical | 57.4% | 2016-10-28 |
| CVE-2017-6526 EXP | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected admi… | Patch early | 9.8 critical | 57.4% | 2017-03-09 |
| CVE-2020-15922 EXP | There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) pr… | Patch early | 9.8 critical | 57.3% | 2020-07-24 |
| CVE-2019-5029 EXP | An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands s… | Patch early | 9.8 critical | 57.2% | 2019-11-13 |
| CVE-2019-5434 EXP | An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in t… | Patch early | 9.8 critical | 57% | 2019-05-06 |
| CVE-2021-45428 EXP | TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HT… | Patch early | 9.8 critical | 56.9% | 2022-01-03 |
| CVE-2017-6361 EXP | QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors. | Patch early | 9.8 critical | 56.8% | 2017-03-23 |
| CVE-2018-12634 EXP | CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html… | Patch early | 9.8 critical | 56.4% | 2018-06-22 |
| CVE-2018-17173 EXP | LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. | Patch early | 9.8 critical | 56.2% | 2018-09-21 |
| CVE-2016-3078 EXP | Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffe… | Patch early | 9.8 critical | 56.1% | 2016-08-07 |
| CVE-2011-4908 EXP | TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php. | Patch early | 9.8 critical | 55.8% | 2020-02-12 |
| CVE-2019-8387 EXP | MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. | Patch early | 9.8 critical | 55.7% | 2019-05-08 |
| CVE-2014-7236 EXP | Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenablep… | Patch early | 9.1 critical | 55.6% | 2020-02-17 |
| CVE-2021-43857 EXP | Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched… | Patch early | 9.8 critical | 55.3% | 2021-12-27 |
| CVE-2016-6602 EXP | ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartex… | Patch early | 9.8 critical | 55.1% | 2017-01-23 |
| CVE-2022-36267 EXP | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can… | Patch early | 9.8 critical | 54.5% | 2022-08-08 |
| CVE-2022-24562 EXP | In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the enti… | Patch early | 9.8 critical | 54.5% | 2022-06-16 |
| CVE-2024-11972 EXP | The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install an… | Patch early | 9.8 critical | 54.5% | 2024-12-31 |
| CVE-2025-49132 EXP | Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespac… | Patch early | 10.0 critical | 54.5% | 2025-06-20 |
| CVE-2021-36356 EXP | KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary e… | Patch early | 9.8 critical | 54.4% | 2021-08-31 |
| CVE-2018-5347 EXP | Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because… | Patch early | 9.8 critical | 54.2% | 2018-01-12 |
| CVE-2019-6441 EXP | An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The passw… | Patch early | 9.8 critical | 53.6% | 2019-03-21 |
| CVE-2017-17932 EXP | A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute ar… | Patch early | 9.8 critical | 53.6% | 2017-12-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt