CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,528 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-6553 EXP | Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server v… | Patch early | 9.8 critical | 42.3% | 2017-04-29 |
| CVE-2013-2573 EXP | A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G,… | Patch early | 9.8 critical | 42.2% | 2020-01-29 |
| CVE-2009-1936 EXP | _functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attac… | Patch early | 9.8 critical | 42.2% | 2009-06-05 |
| CVE-2014-6436 EXP | Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in oppo… | Patch early | 9.8 critical | 42.1% | 2018-01-12 |
| CVE-2018-3811 EXP | SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL q… | Patch early | 9.8 critical | 42% | 2018-01-01 |
| CVE-2016-10074 EXP | The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail… | Patch early | 9.8 critical | 41.8% | 2016-12-30 |
| CVE-2013-1595 EXP | A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field se… | Patch early | 9.8 critical | 41.6% | 2020-01-24 |
| CVE-2024-0132 EXP | NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a sp… | Patch early | 9.0 critical | 40.8% | 2024-09-26 |
| CVE-2019-8050 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 40.6% | 2019-08-20 |
| CVE-2015-4455 EXP | Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows… | Patch early | 9.8 critical | 40.6% | 2017-05-23 |
| CVE-2021-45092 EXP | Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter. | Patch early | 9.8 critical | 40.6% | 2021-12-16 |
| CVE-2013-1599 EXP | A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01,… | Patch early | 9.8 critical | 40.4% | 2020-01-28 |
| CVE-2020-24217 EXP | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentic… | Patch early | 9.8 critical | 40.3% | 2020-10-06 |
| CVE-2019-7442 EXP | An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attacker… | Patch early | 9.8 critical | 40% | 2019-05-08 |
| CVE-2019-7269 EXP | Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution. | Patch early | 9.8 critical | 40% | 2019-07-02 |
| CVE-2025-7441 EXP | The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs th… | Patch early | 9.8 critical | 39.8% | 2025-08-16 |
| CVE-2018-10088 EXP | Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725. | Patch early | 9.8 critical | 39.7% | 2018-06-08 |
| CVE-2017-17968 EXP | A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbi… | Patch early | 9.8 critical | 39.6% | 2017-12-29 |
| CVE-2023-2068 EXP | The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using t… | Patch early | 9.8 critical | 39.6% | 2023-06-27 |
| CVE-2019-17240 EXP | bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-… | Patch early | 9.8 critical | 39.6% | 2019-10-06 |
| CVE-2017-12943 EXP | D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path trav… | Patch early | 9.8 critical | 39.2% | 2017-08-18 |
| CVE-2020-25494 EXP | Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels paramete… | Patch early | 9.8 critical | 39.2% | 2020-12-18 |
| CVE-2018-5262 EXP | A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context… | Patch early | 9.8 critical | 39.1% | 2018-01-12 |
| CVE-2018-17440 EXP | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has… | Patch early | 9.8 critical | 38.5% | 2018-10-08 |
| CVE-2016-10034 EXP | The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before… | Patch early | 9.8 critical | 38.4% | 2016-12-30 |
| CVE-2021-3817 EXP | wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command | Patch early | 9.8 critical | 38.4% | 2021-12-09 |
| CVE-2018-14009 EXP | Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689. | Patch early | 9.8 critical | 38% | 2018-07-12 |
| CVE-2019-10945 EXP | An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to ac… | Patch early | 9.8 critical | 38% | 2019-04-10 |
| CVE-2014-5007 EXP | Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Provid… | Patch early | 9.8 critical | 37.3% | 2020-01-17 |
| CVE-2022-25359 EXP | On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files. | Patch early | 9.1 critical | 37.3% | 2022-02-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt