CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,587 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-6315 EXP | Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx. | Patch early | 9.8 critical | 16.6% | 2017-09-19 |
| CVE-2017-8051 EXP | Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of t… | Patch early | 9.8 critical | 16.5% | 2017-04-21 |
| CVE-2018-13784 EXP | PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php. | Patch early | 9.1 critical | 16.5% | 2018-07-09 |
| CVE-2018-18761 EXP | SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. | Patch early | 9.8 critical | 16.5% | 2018-11-16 |
| CVE-2025-20125 EXP | A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information,… | Patch early | 9.1 critical | 16.4% | 2025-02-05 |
| CVE-2017-11151 EXP | A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files wit… | Patch early | 9.8 critical | 16.3% | 2017-08-08 |
| CVE-2018-14485 EXP | BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. | Patch early | 9.8 critical | 16.3% | 2019-05-07 |
| CVE-2012-6649 EXP | WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload. | Patch early | 9.8 critical | 16.3% | 2020-01-23 |
| CVE-2020-11749 EXP | Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can tri… | Patch early | 9.0 critical | 16.2% | 2020-07-13 |
| CVE-2013-2571 EXP | Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request… | Patch early | 9.8 critical | 16.2% | 2020-01-28 |
| CVE-2021-36711 EXP | WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled. | Patch early | 9.8 critical | 16.1% | 2022-07-16 |
| CVE-2019-8375 EXP | The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script… | Patch early | 9.8 critical | 16.1% | 2019-02-24 |
| CVE-2013-7137 EXP | The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting th… | Patch early | 9.8 critical | 16.1% | 2014-01-26 |
| CVE-2005-2103 EXP | Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly e… | Patch early | 9.8 critical | 16.1% | 2005-08-16 |
| CVE-2015-8396 EXP | Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDC… | Patch early | 10.0 critical | 16% | 2016-01-12 |
| CVE-2019-8045 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 16% | 2019-08-20 |
| CVE-2017-12785 EXP | The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, is prone to a… | Patch early | 9.8 critical | 16% | 2017-08-22 |
| CVE-2020-23935 EXP | Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". | Patch early | 9.8 critical | 15.9% | 2020-08-20 |
| CVE-2020-10230 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parame… | Patch early | 9.8 critical | 15.8% | 2020-03-16 |
| CVE-2016-7866 EXP | Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code… | Patch early | 9.8 critical | 15.8% | 2016-12-15 |
| CVE-2017-3549 EXP | Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affec… | Patch early | 9.1 critical | 15.8% | 2017-04-24 |
| CVE-2025-4094 EXP | The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightfo… | Patch early | 9.8 critical | 15.8% | 2025-05-21 |
| CVE-2021-43136 EXP | An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platfor… | Patch early | 9.8 critical | 15.7% | 2021-11-10 |
| CVE-2017-12965 EXP | Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter. | Patch early | 9.8 critical | 15.7% | 2017-08-23 |
| CVE-2021-38759 EXP | Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges. | Patch early | 9.8 critical | 15.7% | 2021-12-07 |
| CVE-2015-8352 EXP | Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act… | Patch early | 9.8 critical | 15.6% | 2017-08-24 |
| CVE-2017-15580 EXP | osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's co… | Patch early | 9.8 critical | 15.6% | 2017-10-23 |
| CVE-2014-6437 EXP | Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors in… | Patch early | 9.8 critical | 15.5% | 2018-01-12 |
| CVE-2022-2651 EXP | Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5. | Patch early | 9.8 critical | 15.4% | 2022-08-04 |
| CVE-2022-35583 EXP | wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial… | Patch early | 9.8 critical | 15.4% | 2022-08-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt