CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-27823 EXP | An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. | Patch early | 9.8 critical | 53.6% | 2023-05-12 |
| CVE-2019-19844 EXP | Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing… | Patch early | 9.8 critical | 53.6% | 2019-12-18 |
| CVE-2023-29689 EXP | PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vuln… | Patch early | 9.8 critical | 53.5% | 2023-08-04 |
| CVE-2018-7739 EXP | antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demons… | Patch early | 9.8 critical | 53.2% | 2018-03-07 |
| CVE-2019-9760 EXP | FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-controlled machine that sends craf… | Patch early | 9.8 critical | 53.1% | 2019-03-14 |
| CVE-2018-8021 EXP | Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. N… | Patch early | 9.8 critical | 52.8% | 2018-11-07 |
| CVE-2022-31126 EXP | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauth… | Patch early | 10.0 critical | 52.6% | 2022-07-06 |
| CVE-2018-8734 EXP | SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL comm… | Patch early | 9.8 critical | 52.6% | 2018-04-18 |
| CVE-2018-11686 EXP | The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. | Patch early | 9.8 critical | 52.5% | 2019-07-03 |
| CVE-2017-5174 EXP | An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has bee… | Patch early | 9.8 critical | 52.3% | 2017-05-19 |
| CVE-2025-27007 EXP | Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a… | Patch early | 9.8 critical | 51.5% | 2025-05-01 |
| CVE-2016-2345 EXP | Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbit… | Patch early | 9.8 critical | 51.2% | 2016-03-17 |
| CVE-2018-1217 EXP | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affec… | Patch early | 9.8 critical | 50.9% | 2018-04-09 |
| CVE-2021-34646 EXP | Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_ve… | Patch early | 9.8 critical | 50.9% | 2021-08-30 |
| CVE-2019-12518 EXP | Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability. | Patch early | 9.8 critical | 50.7% | 2019-12-02 |
| CVE-2024-25735 EXP | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config… | Patch early | 9.1 critical | 50.6% | 2024-03-27 |
| CVE-2018-19524 EXP | An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 dev… | Patch early | 9.8 critical | 50.5% | 2019-03-21 |
| CVE-2017-16720 EXP | A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the t… | Patch early | 9.8 critical | 50.3% | 2018-01-05 |
| CVE-2017-6465 EXP | Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; howeve… | Patch early | 9.8 critical | 50.3% | 2017-03-10 |
| CVE-2012-3363 EXP | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attac… | Patch early | 9.1 critical | 50.2% | 2013-02-13 |
| CVE-2025-58434 EXP | Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint… | Patch early | 9.8 critical | 49.9% | 2025-09-12 |
| CVE-2016-6909 EXP | Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 a… | Patch early | 9.8 critical | 49.9% | 2016-08-24 |
| CVE-2022-37109 EXP | patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the passwo… | Patch early | 9.8 critical | 49.5% | 2022-11-14 |
| CVE-2018-13862 EXP | Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attackers to reset the authentication… | Patch early | 9.8 critical | 49.3% | 2018-07-17 |
| CVE-2023-3710 EXP | Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 v… | Patch early | 9.9 critical | 49% | 2023-09-12 |
| CVE-2018-9126 EXP | The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credent… | Patch early | 9.8 critical | 48.9% | 2018-04-04 |
| CVE-2013-2568 EXP | A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a re… | Patch early | 9.8 critical | 48.5% | 2020-01-29 |
| CVE-2017-9232 EXP | Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege… | Patch early | 9.8 critical | 48.5% | 2017-05-28 |
| CVE-2020-5377 EXP | Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote atta… | Patch early | 9.1 critical | 48.3% | 2020-07-28 |
| CVE-2018-8096 EXP | Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","V… | Patch early | 9.8 critical | 48.2% | 2018-03-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt