CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,528 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-27964 EXP | SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFil… | Patch early | 9.8 critical | 47.5% | 2021-03-05 |
| CVE-2018-5767 EXP | An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with… | Patch early | 9.8 critical | 47.4% | 2018-02-15 |
| CVE-2015-6834 EXP | Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary… | Patch early | 9.8 critical | 46.8% | 2016-05-16 |
| CVE-2019-9879 EXP | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are all… | Patch early | 9.8 critical | 46.6% | 2019-06-10 |
| CVE-2025-29306 EXP | An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component. | Patch early | 9.8 critical | 46.6% | 2025-03-27 |
| CVE-2023-30145 EXP | Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. | Patch early | 9.8 critical | 46.1% | 2023-05-26 |
| CVE-2015-9323 EXP | The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection. | Patch early | 9.8 critical | 46.1% | 2019-08-16 |
| CVE-2022-35411 EXP | rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, althou… | Patch early | 9.8 critical | 45.7% | 2022-07-08 |
| CVE-2019-6444 EXP | An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data… | Patch early | 9.1 critical | 45.7% | 2019-01-16 |
| CVE-2016-1606 EXP | Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code v… | Patch early | 9.8 critical | 45.6% | 2016-07-03 |
| CVE-2021-29003 EXP | Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as… | Patch early | 9.8 critical | 45.4% | 2021-04-13 |
| CVE-2018-15839 EXP | D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header. | Patch early | 9.8 critical | 45.3% | 2018-08-28 |
| CVE-2020-35313 EXP | A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attack… | Patch early | 9.8 critical | 45.2% | 2021-04-20 |
| CVE-2024-48760 EXP | An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlc… | Patch early | 9.8 critical | 45.1% | 2025-01-14 |
| CVE-2024-42640 EXP | angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allow… | Patch early | 9.8 critical | 45.1% | 2024-10-11 |
| CVE-2022-0332 EXP | A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching u… | Patch early | 9.8 critical | 44.9% | 2022-01-25 |
| CVE-2019-8341 EXP | An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" paramet… | Patch early | 9.8 critical | 44.8% | 2019-02-15 |
| CVE-2018-11510 EXP | The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by… | Patch early | 9.8 critical | 44.3% | 2018-06-28 |
| CVE-2020-36847 EXP | The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which… | Patch early | 9.8 critical | 44.2% | 2025-07-12 |
| CVE-2020-13693 EXP | An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled. | Patch early | 9.8 critical | 43.9% | 2020-05-29 |
| CVE-2014-8687 EXP | Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use o… | Patch early | 9.8 critical | 43.8% | 2017-06-08 |
| CVE-2019-9618 EXP | The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter. | Patch early | 9.8 critical | 43.8% | 2019-05-13 |
| CVE-2022-0482 EXP | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. | Patch early | 9.1 critical | 43.7% | 2022-03-09 |
| CVE-2018-6317 EXP | The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remo… | Patch early | 9.1 critical | 43.7% | 2018-02-02 |
| CVE-2017-10366 EXP | Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor). Supported versi… | Patch early | 9.8 critical | 43.5% | 2017-10-19 |
| CVE-2010-1205 EXP | Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to exe… | Patch early | 9.8 critical | 43.4% | 2010-06-30 |
| CVE-2017-11346 EXP | Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk… | Patch early | 9.8 critical | 43.3% | 2017-07-17 |
| CVE-2025-68664 EXP | LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability… | Patch early | 9.3 critical | 42.9% | 2025-12-23 |
| CVE-2018-1235 EXP | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauth… | Patch early | 9.8 critical | 42.9% | 2018-05-29 |
| CVE-2020-9374 EXP | On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends spec… | Patch early | 9.8 critical | 42.7% | 2020-02-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt