CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,529 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-24629 EXP | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in… | Patch early | 9.8 critical | 37.2% | 2023-05-29 |
| CVE-2016-3074 EXP | Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentiall… | Patch early | 9.8 critical | 37.2% | 2016-04-26 |
| CVE-2014-8686 EXP | CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when t… | Patch early | 9.8 critical | 37.2% | 2017-09-19 |
| CVE-2018-14064 EXP | The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80. | Patch early | 9.8 critical | 37.2% | 2018-07-15 |
| CVE-2015-8351 EXP | PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote au… | Patch early | 9.0 critical | 37% | 2017-09-11 |
| CVE-2015-6835 EXP | The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow… | Patch early | 9.8 critical | 37% | 2016-05-16 |
| CVE-2019-6814 EXP | A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to conf… | Patch early | 9.8 critical | 36.7% | 2019-05-22 |
| CVE-2017-16887 EXP | The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized… | Patch early | 9.8 critical | 36.6% | 2018-01-12 |
| CVE-2017-14322 EXP | The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attacke… | Patch early | 9.8 critical | 36.5% | 2017-10-18 |
| CVE-2021-46424 EXP | Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system int… | Patch early | 9.1 critical | 36.5% | 2022-04-27 |
| CVE-2018-6580 EXP | Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request. | Patch early | 9.8 critical | 36.3% | 2018-02-02 |
| CVE-2013-4976 EXP | Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials | Patch early | 9.8 critical | 36.1% | 2019-12-27 |
| CVE-2021-43936 EXP | The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the p… | Patch early | 10.0 critical | 35.8% | 2021-12-06 |
| CVE-2021-31251 EXP | An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a… | Patch early | 9.8 critical | 35.7% | 2021-06-04 |
| CVE-2022-0848 EXP | OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11. | Patch early | 9.8 critical | 35.4% | 2022-03-04 |
| CVE-2020-24214 EXP | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP r… | Patch early | 9.8 critical | 35.4% | 2020-10-06 |
| CVE-2017-8225 EXP | On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentica… | Patch early | 9.8 critical | 35.4% | 2017-04-25 |
| CVE-2020-35391 EXP | Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request… | Patch early | 9.6 critical | 35.2% | 2021-01-01 |
| CVE-2017-11282 EXP | Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code exe… | Patch early | 9.8 critical | 34.8% | 2017-12-01 |
| CVE-2016-9150 EXP | Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1… | Patch early | 9.8 critical | 34.8% | 2016-11-19 |
| CVE-2019-9880 EXP | An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacke… | Patch early | 9.1 critical | 34.8% | 2019-06-10 |
| CVE-2019-16451 EXP | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | Patch early | 9.8 critical | 34.7% | 2019-12-19 |
| CVE-2019-8048 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 34.6% | 2019-08-20 |
| CVE-2017-16930 EXP | The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack… | Patch early | 9.8 critical | 34.3% | 2017-12-05 |
| CVE-2017-5792 EXP | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found. | Patch early | 9.8 critical | 34.3% | 2018-02-15 |
| CVE-2016-2563 EXP | Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denia… | Patch early | 9.8 critical | 34.2% | 2016-04-07 |
| CVE-2017-11281 EXP | Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary c… | Patch early | 9.8 critical | 33.9% | 2017-12-01 |
| CVE-2022-37661 EXP | SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature. | Patch early | 9.8 critical | 33.9% | 2022-09-14 |
| CVE-2017-5375 EXP | JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thun… | Patch early | 9.8 critical | 33.8% | 2018-06-11 |
| CVE-2011-2013 EXP | Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allo… | Patch early | 9.8 critical | 33.7% | 2011-11-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt