CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,603 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-27100 EXP | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software… | Patch early | 9.8 critical | 9.8% | 2023-03-22 |
| CVE-2017-17417 EXP | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is… | Patch early | 9.8 critical | 9.8% | 2018-02-08 |
| CVE-2018-11523 EXP | upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files. | Patch early | 9.8 critical | 9.8% | 2018-05-29 |
| CVE-2013-5945 EXP | Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N wit… | Patch early | 9.8 critical | 9.8% | 2020-02-11 |
| CVE-2017-14089 EXP | An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the Office… | Patch early | 9.8 critical | 9.8% | 2017-10-06 |
| CVE-2019-8662 EXP | This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able… | Patch early | 9.8 critical | 9.8% | 2019-12-18 |
| CVE-2018-5723 EXP | MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account. | Patch early | 9.8 critical | 9.7% | 2018-01-16 |
| CVE-2019-6716 EXP | An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote atta… | Patch early | 9.4 critical | 9.6% | 2019-03-21 |
| CVE-2018-9021 EXP | An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with sp… | Patch early | 9.8 critical | 9.6% | 2018-06-18 |
| CVE-2011-4906 EXP | Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution. | Patch early | 9.8 critical | 9.6% | 2020-02-12 |
| CVE-2022-32272 EXP | OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access con… | Patch early | 9.8 critical | 9.6% | 2022-06-09 |
| CVE-2018-18793 EXP | School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. | Patch early | 9.8 critical | 9.5% | 2018-11-16 |
| CVE-2017-11309 EXP | Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response. | Patch early | 9.6 critical | 9.4% | 2017-11-10 |
| CVE-2026-0926 EXP | The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'parameters[templa… | Patch early | 9.8 critical | 9.4% | 2026-02-19 |
| CVE-2012-5878 EXP | Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in… | Patch early | 9.8 critical | 9.3% | 2020-01-03 |
| CVE-2019-13292 EXP | A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Th… | Patch early | 9.8 critical | 9.3% | 2019-07-04 |
| CVE-2026-4631 EXP | Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitizatio… | Patch early | 9.8 critical | 9.2% | 2026-04-07 |
| CVE-2017-11120 EXP | On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor report frame to trigger an interna… | Patch early | 9.8 critical | 9.1% | 2017-09-28 |
| CVE-2018-12292 EXP | A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3. | Patch early | 9.8 critical | 9.1% | 2018-06-13 |
| CVE-2023-33362 EXP | Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function. | Patch early | 9.8 critical | 9.1% | 2023-05-23 |
| CVE-2016-10043 EXP | An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to OS… | Patch early | 10.0 critical | 9% | 2017-01-31 |
| CVE-2019-9184 EXP | SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the produ… | Patch early | 9.8 critical | 9% | 2019-02-26 |
| CVE-2018-14418 EXP | In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI. | Patch early | 9.8 critical | 9% | 2018-07-20 |
| CVE-2002-1816 EXP | Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via… | Patch early | 9.8 critical | 9% | 2002-12-31 |
| CVE-2022-31056 EXP | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affect… | Patch early | 9.8 critical | 9% | 2022-06-28 |
| CVE-2012-4750 EXP | A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicio… | Patch early | 9.8 critical | 8.9% | 2020-01-13 |
| CVE-2001-1291 EXP | The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or pass… | Patch early | 9.8 critical | 8.9% | 2001-07-12 |
| CVE-2017-4914 EXP | VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote at… | Patch early | 9.8 critical | 8.8% | 2017-06-07 |
| CVE-2017-17111 EXP | Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request. | Patch early | 9.8 critical | 8.8% | 2017-12-11 |
| CVE-2011-3642 EXP | Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, a… | Patch early | 9.6 critical | 8.8% | 2020-02-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt