CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,587 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-6558 EXP | iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote a… | Patch early | 9.8 critical | 15.3% | 2017-03-09 |
| CVE-2023-0777 EXP | Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4. | Patch early | 9.8 critical | 15.2% | 2023-02-10 |
| CVE-2018-11311 EXP | A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server o… | Patch early | 9.1 critical | 15.2% | 2018-05-20 |
| CVE-2007-1383 EXP | Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this co… | Patch early | 9.8 critical | 15.2% | 2007-03-10 |
| CVE-2017-17672 EXP | In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circums… | Patch early | 9.8 critical | 15.2% | 2017-12-14 |
| CVE-2013-6924 EXP | Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip… | Patch early | 9.8 critical | 15.2% | 2017-10-11 |
| CVE-2014-5091 EXP | A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user… | Patch early | 9.8 critical | 15.2% | 2020-02-07 |
| CVE-2018-18322 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_… | Patch early | 9.8 critical | 15.1% | 2018-10-15 |
| CVE-2015-2780 EXP | Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an execut… | Patch early | 9.8 critical | 15.1% | 2017-10-16 |
| CVE-2019-8024 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 15.1% | 2019-08-20 |
| CVE-2016-5228 EXP | Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11997 and 9.… | Patch early | 9.8 critical | 15.1% | 2016-07-03 |
| CVE-2016-3974 EXP | XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial… | Patch early | 9.1 critical | 15.1% | 2016-04-07 |
| CVE-2018-11586 EXP | XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct… | Patch early | 9.8 critical | 15% | 2018-06-05 |
| CVE-2023-22855 EXP | Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is… | Patch early | 9.8 critical | 14.8% | 2023-02-15 |
| CVE-2017-14243 EXP | An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administra… | Patch early | 9.8 critical | 14.8% | 2017-09-17 |
| CVE-2008-1160 EXP | ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attac… | Patch early | 9.8 critical | 14.8% | 2008-03-25 |
| CVE-2002-0083 EXP | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | Patch early | 9.8 critical | 14.7% | 2002-03-15 |
| CVE-2026-58138 EXP | Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrar… | Patch early | 9.8 critical | 14.7% | 2026-06-30 |
| CVE-2017-6972 EXP | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root… | Patch early | 9.8 critical | 14.6% | 2017-03-22 |
| CVE-2017-2641 EXP | In Moodle 2.x and 3.x, SQL injection can occur via user preferences. | Patch early | 9.8 critical | 14.5% | 2017-03-26 |
| CVE-2014-4170 EXP | A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script,… | Patch early | 9.8 critical | 14.5% | 2020-02-13 |
| CVE-2018-9248 EXP | FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header. | Patch early | 9.8 critical | 14.5% | 2018-04-04 |
| CVE-2019-8044 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 14.5% | 2019-08-20 |
| CVE-2019-3025 EXP | Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported version that is affected is 5.7. Di… | Patch early | 9.0 critical | 14.5% | 2019-10-16 |
| CVE-2019-13597 EXP | _s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one can… | Patch early | 9.8 critical | 14.3% | 2019-07-14 |
| CVE-2018-11742 EXP | NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI. | Patch early | 9.8 critical | 14.3% | 2018-12-26 |
| CVE-2017-6880 EXP | Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other… | Patch early | 9.8 critical | 14.3% | 2017-03-17 |
| CVE-2015-7246 EXP | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account,… | Patch early | 9.8 critical | 14.3% | 2017-04-24 |
| CVE-2023-33584 EXP | Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries exe… | Patch early | 9.8 critical | 14.2% | 2023-06-21 |
| CVE-2015-9098 EXP | In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in the ability… | Patch early | 9.8 critical | 14.1% | 2017-06-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt