CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,553 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-3278 EXP | Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an… | Patch early | 9.8 critical | 25.3% | 2021-01-26 |
| CVE-2017-12786 EXP | Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwit… | Patch early | 9.8 critical | 25.3% | 2017-08-22 |
| CVE-2020-35948 EXP | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify ar… | Patch early | 9.9 critical | 24.9% | 2021-01-01 |
| CVE-2018-19864 EXP | NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer ove… | Patch early | 9.8 critical | 24.8% | 2018-12-05 |
| CVE-2019-16119 EXP | SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album… | Patch early | 9.8 critical | 24.8% | 2019-09-08 |
| CVE-2016-5108 EXP | Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a… | Patch early | 9.8 critical | 24.7% | 2016-06-08 |
| CVE-2017-3061 EXP | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. Successful exploitation coul… | Patch early | 9.8 critical | 24.7% | 2017-04-12 |
| CVE-2017-3076 EXP | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC module. Successful exploitati… | Patch early | 9.8 critical | 24.7% | 2017-06-20 |
| CVE-2019-5893 EXP | Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter. | Patch early | 9.8 critical | 24.7% | 2019-01-10 |
| CVE-2014-4650 EXP | The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remot… | Patch early | 9.8 critical | 24.7% | 2020-02-20 |
| CVE-2013-7052 EXP | D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script | Patch early | 9.8 critical | 24.7% | 2020-02-04 |
| CVE-2016-3645 EXP | Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:S… | Patch early | 9.8 critical | 24.6% | 2016-06-30 |
| CVE-2017-12787 EXP | A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviS… | Patch early | 9.8 critical | 24.6% | 2017-08-22 |
| CVE-2019-13360 EXP | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge o… | Patch early | 9.8 critical | 24.5% | 2019-07-16 |
| CVE-2018-11652 EXP | CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP respons… | Patch early | 9.8 critical | 24.4% | 2018-06-01 |
| CVE-2013-1592 EXP | A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Serve… | Patch early | 9.8 critical | 24.4% | 2020-01-23 |
| CVE-2019-13577 EXP | SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature liste… | Patch early | 9.8 critical | 24.4% | 2019-07-17 |
| CVE-2018-12584 EXP | The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a denia… | Patch early | 9.8 critical | 24.3% | 2018-07-16 |
| CVE-2024-25830 EXP | F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker… | Patch early | 9.8 critical | 24% | 2024-02-29 |
| CVE-2017-8798 EXP | Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspec… | Patch early | 9.8 critical | 24% | 2017-05-11 |
| CVE-2014-8322 EXP | Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code… | Patch early | 9.8 critical | 23.9% | 2020-01-31 |
| CVE-2024-27747 EXP | File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Imag… | Patch early | 9.8 critical | 23.6% | 2024-03-01 |
| CVE-2018-6396 EXP | SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or… | Patch early | 9.8 critical | 23.6% | 2018-02-17 |
| CVE-2018-5997 EXP | An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it… | Patch early | 9.8 critical | 23.5% | 2018-01-25 |
| CVE-2023-37629 EXP | Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig… | Patch early | 9.8 critical | 23.3% | 2023-07-12 |
| CVE-2016-9682 EXP | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrati… | Patch early | 9.8 critical | 23.3% | 2017-02-22 |
| CVE-2005-3120 EXP | Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article… | Patch early | 9.8 critical | 23.3% | 2005-10-17 |
| CVE-2013-1360 EXP | An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Ma… | Patch early | 9.8 critical | 23.2% | 2020-02-11 |
| CVE-2019-7265 EXP | Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH). | Patch early | 9.8 critical | 23.1% | 2019-07-02 |
| CVE-2021-44567 EXP | An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php. | Patch early | 9.8 critical | 23.1% | 2022-02-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt