CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,603 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-17739 EXP | The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an atta… | Patch early | 9.8 critical | 11.9% | 2017-12-18 |
| CVE-2021-42325 EXP | Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name. | Patch early | 9.8 critical | 11.8% | 2021-10-12 |
| CVE-2009-2168 EXP | cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are… | Patch early | 9.8 critical | 11.8% | 2009-06-22 |
| CVE-2014-7279 EXP | The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority"… | Patch early | 9.8 critical | 11.7% | 2017-03-23 |
| CVE-2019-17132 EXP | vBulletin through 5.5.4 mishandles custom avatars. | Patch early | 9.8 critical | 11.7% | 2019-10-04 |
| CVE-2017-6506 EXP | In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. T… | Patch early | 9.8 critical | 11.7% | 2017-03-10 |
| CVE-2017-3897 EXP | A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security… | Patch early | 9.8 critical | 11.7% | 2017-09-01 |
| CVE-2016-6566 EXP | The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software ver… | Patch early | 9.8 critical | 11.6% | 2018-07-13 |
| CVE-2018-18957 EXP | An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c. | Patch early | 9.8 critical | 11.6% | 2018-11-05 |
| CVE-2016-9683 EXP | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative i… | Patch early | 9.8 critical | 11.6% | 2017-02-22 |
| CVE-2018-5724 EXP | MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi. | Patch early | 9.8 critical | 11.5% | 2018-01-16 |
| CVE-2019-10709 EXP | AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potenti… | Patch early | 9.8 critical | 11.5% | 2019-09-04 |
| CVE-2022-38580 EXP | Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). | Patch early | 9.8 critical | 11.5% | 2022-10-25 |
| CVE-2017-2523 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | Patch early | 9.8 critical | 11.5% | 2017-05-22 |
| CVE-2014-9148 EXP | Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administr… | Patch early | 9.8 critical | 11.4% | 2017-10-16 |
| CVE-2022-22831 EXP | An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header. | Patch early | 9.8 critical | 11.4% | 2022-02-06 |
| CVE-2024-40422 EXP | The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker ca… | Patch early | 9.1 critical | 11.4% | 2024-07-24 |
| CVE-2017-9430 EXP | Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified ot… | Patch early | 9.8 critical | 11.3% | 2017-06-05 |
| CVE-2020-25762 EXP | An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and… | Patch early | 9.1 critical | 11.3% | 2020-09-30 |
| CVE-2017-17759 EXP | Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the confi… | Patch early | 9.8 critical | 11.3% | 2017-12-19 |
| CVE-2018-11511 EXP | The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' o… | Patch early | 9.8 critical | 11.3% | 2018-08-16 |
| CVE-2000-0944 EXP | CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allow… | Patch early | 9.8 critical | 11.3% | 2000-12-19 |
| CVE-2017-1002001 EXP | Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedio… | Patch early | 9.8 critical | 11.1% | 2017-09-14 |
| CVE-2015-4667 EXP | Multiple hardcoded credentials in Xsuite 2.x. | Patch early | 9.8 critical | 11.1% | 2017-09-25 |
| CVE-2022-34668 EXP | NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged networ… | Patch early | 9.8 critical | 10.9% | 2022-08-29 |
| CVE-2022-41544 EXP | GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php. | Patch early | 9.8 critical | 10.8% | 2022-10-18 |
| CVE-2020-15160 EXP | PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with loca… | Patch early | 9.8 critical | 10.8% | 2020-09-24 |
| CVE-1999-0426 EXP | The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing. | Patch early | 9.8 critical | 10.8% | 1999-03-01 |
| CVE-2019-16702 EXP | Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs parameter to the /LoginAdmin URI… | Patch early | 9.8 critical | 10.7% | 2019-09-23 |
| CVE-2018-20218 EXP | An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without… | Patch early | 9.8 critical | 10.7% | 2019-03-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt