CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,529 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-5815 EXP | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | Patch early | 9.8 critical | 33.7% | 2018-02-15 |
| CVE-2017-7588 EXP | On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affecte… | Patch early | 9.8 critical | 33.6% | 2017-04-12 |
| CVE-2021-31761 EXP | Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature. | Patch early | 9.6 critical | 33.6% | 2021-04-25 |
| CVE-2017-16885 EXP | Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Chang… | Patch early | 9.8 critical | 33.5% | 2018-01-12 |
| CVE-2018-11094 EXP | An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasic… | Patch early | 9.8 critical | 33.4% | 2018-05-15 |
| CVE-2016-0801 EXP | The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to exe… | Patch early | 9.8 critical | 33.1% | 2016-02-07 |
| CVE-2017-6187 EXP | Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET re… | Patch early | 9.8 critical | 33.1% | 2017-02-22 |
| CVE-2017-3241 EXP | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java… | Patch early | 9.0 critical | 32.8% | 2017-01-27 |
| CVE-2026-4257 EXP | The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in al… | Patch early | 9.8 critical | 32.8% | 2026-03-30 |
| CVE-2022-31885 EXP | Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts. | Patch early | 9.8 critical | 32.8% | 2022-06-28 |
| CVE-2018-15534 EXP | Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a d… | Patch early | 9.8 critical | 32.4% | 2018-08-21 |
| CVE-2017-6026 EXP | A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.1… | Patch early | 9.1 critical | 31.8% | 2017-06-30 |
| CVE-2018-13415 EXP | In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.… | Patch early | 9.8 critical | 31.8% | 2018-08-13 |
| CVE-2023-36355 EXP | TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows… | Patch early | 9.9 critical | 31.7% | 2023-06-22 |
| CVE-2019-6714 EXP | An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unaut… | Patch early | 9.8 critical | 31.7% | 2019-03-21 |
| CVE-2012-3807 EXP | Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution. | Patch early | 9.8 critical | 31.6% | 2020-01-09 |
| CVE-2017-3078 EXP | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Succe… | Patch early | 9.8 critical | 30.9% | 2017-06-20 |
| CVE-2018-7300 EXP | Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows… | Patch early | 9.8 critical | 30.6% | 2018-02-22 |
| CVE-2016-2385 EXP | Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows re… | Patch early | 9.8 critical | 30.5% | 2016-04-11 |
| CVE-2016-7182 EXP | The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2… | Patch early | 9.8 critical | 30.3% | 2016-10-14 |
| CVE-2018-10718 EXP | Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary c… | Patch early | 10.0 critical | 30.2% | 2018-05-03 |
| CVE-2024-22836 EXP | An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to… | Patch early | 9.8 critical | 30% | 2024-02-08 |
| CVE-2017-0561 EXP | A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of th… | Patch early | 9.8 critical | 29.8% | 2017-04-07 |
| CVE-2026-3891 EXP | The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation… | Patch early | 9.8 critical | 29.7% | 2026-03-13 |
| CVE-2017-5173 EXP | An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An im… | Patch early | 9.8 critical | 29.6% | 2017-05-19 |
| CVE-2012-6664 EXP | Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write… | Patch early | 9.1 critical | 29.5% | 2024-06-21 |
| CVE-2020-14011 EXP | Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is… | Patch early | 9.8 critical | 29.5% | 2020-06-15 |
| CVE-2017-11517 EXP | Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote attackers to execute arbitrary c… | Patch early | 9.8 critical | 29.1% | 2017-07-21 |
| CVE-2019-7274 EXP | Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root. | Patch early | 9.8 critical | 29% | 2019-07-01 |
| CVE-2010-0211 EXP | The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows rem… | Patch early | 9.8 critical | 28.5% | 2010-07-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt