CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,612 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-17055 EXP | Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involv… | Patch early | 9.0 critical | 8.7% | 2017-12-07 |
| CVE-2016-5678 EXP | NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain admin… | Patch early | 9.8 critical | 8.7% | 2016-08-31 |
| CVE-2017-8224 EXP | Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET. | Patch early | 9.8 critical | 8.7% | 2017-04-25 |
| CVE-2018-7318 EXP | SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order p… | Patch early | 9.8 critical | 8.7% | 2018-02-22 |
| CVE-2017-17110 EXP | Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request. | Patch early | 9.8 critical | 8.6% | 2017-12-11 |
| CVE-2018-11736 EXP | An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the… | Patch early | 9.8 critical | 8.6% | 2018-06-05 |
| CVE-2023-27290 EXP | Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require… | Patch early | 9.1 critical | 8.6% | 2023-03-03 |
| CVE-2018-10575 EXP | An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged S… | Patch early | 9.8 critical | 8.5% | 2018-04-30 |
| CVE-2017-2800 EXP | A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate vali… | Patch early | 9.8 critical | 8.5% | 2017-05-24 |
| CVE-2018-9302 EXP | SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TC… | Patch early | 9.1 critical | 8.5% | 2018-05-02 |
| CVE-2013-4743 EXP | Static HTTP Server 1.0 has a Local Overflow | Patch early | 9.8 critical | 8.4% | 2019-12-27 |
| CVE-2015-3313 EXP | SQL injection vulnerability in WordPress Community Events plugin before 1.4. | Patch early | 9.8 critical | 8.3% | 2017-09-07 |
| CVE-2026-24479 EXP | HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj… | Patch early | 9.8 critical | 8.3% | 2026-01-27 |
| CVE-2017-10682 EXP | SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_fa… | Patch early | 9.8 critical | 8.3% | 2017-06-29 |
| CVE-2017-14702 EXP | ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object deserializa… | Patch early | 9.8 critical | 8.3% | 2017-09-30 |
| CVE-2022-24263 EXP | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email p… | Patch early | 9.8 critical | 8.2% | 2022-01-31 |
| CVE-2019-10664 EXP | Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp. | Patch early | 9.8 critical | 8.2% | 2019-03-31 |
| CVE-2001-0766 EXP | Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some character… | Patch early | 9.8 critical | 8.2% | 2001-10-18 |
| CVE-2019-18873 EXP | FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user accoun… | Patch early | 9.0 critical | 8.2% | 2019-11-12 |
| CVE-2024-50477 EXP | Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentica… | Patch early | 9.8 critical | 8.1% | 2024-10-28 |
| CVE-2019-9623 EXP | Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php. | Patch early | 9.8 critical | 8.1% | 2019-03-07 |
| CVE-2019-7671 EXP | Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may a… | Patch early | 9.0 critical | 8.1% | 2019-06-05 |
| CVE-2026-1830 EXP | The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insuffici… | Patch early | 9.8 critical | 8.1% | 2026-04-09 |
| CVE-2023-1934 EXP | The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Pres… | Patch early | 9.8 critical | 8.1% | 2023-05-12 |
| CVE-2014-4912 EXP | An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation. | Patch early | 9.8 critical | 8.1% | 2018-03-22 |
| CVE-2018-7316 EXP | Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action. | Patch early | 9.8 critical | 8.1% | 2018-02-22 |
| CVE-2017-16783 EXP | In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter. | Patch early | 9.8 critical | 8% | 2017-11-10 |
| CVE-2019-19245 EXP | NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quote… | Patch early | 9.8 critical | 7.9% | 2019-12-02 |
| CVE-2023-39115 EXP | install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document. | Patch early | 9.8 critical | 7.9% | 2023-08-16 |
| CVE-2016-6256 EXP | SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcelle… | Patch early | 9.6 critical | 7.9% | 2017-05-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt