CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,558 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-1930 EXP | In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker t… | Patch early | 9.8 critical | 20.5% | 2019-11-14 |
| CVE-2019-14348 EXP | The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-york… | Patch early | 9.8 critical | 20.5% | 2019-08-05 |
| CVE-2022-31125 EXP | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauth… | Patch early | 10.0 critical | 20.3% | 2022-07-06 |
| CVE-2021-27828 EXP | SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavi… | Patch early | 9.1 critical | 20.3% | 2021-06-01 |
| CVE-2018-13416 EXP | In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) att… | Patch early | 9.8 critical | 20.2% | 2018-08-03 |
| CVE-2018-5973 EXP | SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryI… | Patch early | 9.8 critical | 20.1% | 2018-01-25 |
| CVE-2017-4901 EXP | The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory acce… | Patch early | 9.9 critical | 19.9% | 2017-06-08 |
| CVE-2019-9791 EXP | The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMo… | Patch early | 9.8 critical | 19.9% | 2019-04-26 |
| CVE-2007-1399 EXP | Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to e… | Patch early | 9.8 critical | 19.8% | 2007-03-10 |
| CVE-2021-43617 EXP | Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttr… | Patch early | 9.8 critical | 19.8% | 2021-11-14 |
| CVE-2018-5726 EXP | MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request, as demonstrated by the usernam… | Patch early | 9.8 critical | 19.8% | 2018-01-16 |
| CVE-2020-24215 EXP | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP re… | Patch early | 9.8 critical | 19.8% | 2020-10-06 |
| CVE-2019-8049 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 19.7% | 2019-08-20 |
| CVE-2016-6175 EXP | Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header… | Patch early | 9.8 critical | 19.7% | 2017-02-07 |
| CVE-2019-8385 EXP | An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability… | Patch early | 9.8 critical | 19.6% | 2019-06-05 |
| CVE-2016-0951 EXP | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a… | Patch early | 9.8 critical | 19.6% | 2016-02-10 |
| CVE-2016-0952 EXP | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a… | Patch early | 9.8 critical | 19.6% | 2016-02-10 |
| CVE-2016-0953 EXP | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a… | Patch early | 9.8 critical | 19.6% | 2016-02-10 |
| CVE-2021-3018 EXP | ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print… | Patch early | 9.8 critical | 19.5% | 2021-01-05 |
| CVE-2024-24496 EXP | An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tr… | Patch early | 9.8 critical | 19.5% | 2024-02-08 |
| CVE-2016-4071 EXP | Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows r… | Patch early | 9.8 critical | 19.5% | 2016-05-20 |
| CVE-2016-4372 EXP | HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02,… | Patch early | 9.8 critical | 19.4% | 2016-07-15 |
| CVE-2025-64459 EXP | An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `Que… | Patch early | 9.1 critical | 19.4% | 2025-11-05 |
| CVE-2017-14094 EXP | A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution… | Patch early | 9.8 critical | 19.4% | 2018-01-19 |
| CVE-2017-7997 EXP | Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1) show_prn parameter… | Patch early | 9.8 critical | 19.3% | 2018-01-08 |
| CVE-2019-19208 EXP | Codiad Web IDE through 2.8.4 allows PHP Code injection. | Patch early | 9.8 critical | 19.2% | 2020-03-16 |
| CVE-2016-6598 EXP | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service conta… | Patch early | 9.8 critical | 19.2% | 2018-01-30 |
| CVE-2013-3684 EXP | NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload | Patch early | 9.8 critical | 19.2% | 2020-02-11 |
| CVE-2016-2208 EXP | The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denia… | Patch early | 9.1 critical | 19.2% | 2016-05-19 |
| CVE-2017-16949 EXP | An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the at… | Patch early | 9.8 critical | 19.2% | 2017-12-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt