CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,612 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-27422 EXP | In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link t… | Patch early | 9.8 critical | 7.9% | 2020-11-16 |
| CVE-2022-34128 EXP | The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php. | Patch early | 9.8 critical | 7.8% | 2023-04-16 |
| CVE-2004-0285 EXP | PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers t… | Patch early | 9.8 critical | 7.8% | 2004-11-23 |
| CVE-2024-39930 EXP | The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attac… | Patch early | 9.9 critical | 7.7% | 2024-07-04 |
| CVE-2017-15990 EXP | Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. | Patch early | 9.8 critical | 7.7% | 2017-10-31 |
| CVE-2017-16935 EXP | Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restri… | Patch early | 9.8 critical | 7.7% | 2017-11-24 |
| CVE-2017-17761 EXP | An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) u… | Patch early | 9.8 critical | 7.5% | 2017-12-19 |
| CVE-2001-1339 EXP | Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for re… | Patch early | 9.8 critical | 7.5% | 2001-05-24 |
| CVE-2014-2072 EXP | Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks | Patch early | 9.8 critical | 7.4% | 2020-01-08 |
| CVE-2012-2226 EXP | Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute… | Patch early | 9.8 critical | 7.4% | 2020-01-09 |
| CVE-2004-0030 EXP | PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remot… | Patch early | 9.8 critical | 7.3% | 2004-01-20 |
| CVE-2020-6170 EXP | An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the H… | Patch early | 9.8 critical | 7.3% | 2020-01-08 |
| CVE-2018-9035 EXP | CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to… | Patch early | 9.6 critical | 7.3% | 2018-04-04 |
| CVE-2014-5087 EXP | A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user exe… | Patch early | 9.8 critical | 7.2% | 2020-02-07 |
| CVE-2021-21276 EXP | Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site… | Patch early | 9.3 critical | 7.2% | 2021-02-01 |
| CVE-2017-11502 EXP | Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321. | Patch early | 9.8 critical | 7.1% | 2017-07-20 |
| CVE-2017-15220 EXP | Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginning with a /../ substring. This… | Patch early | 9.8 critical | 7.1% | 2017-10-11 |
| CVE-2008-5784 EXP | V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to… | Patch early | 9.8 critical | 7.1% | 2008-12-31 |
| CVE-2013-1465 EXP | The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP object… | Patch early | 9.8 critical | 7.1% | 2013-02-08 |
| CVE-2019-16399 EXP | Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory witho… | Patch early | 9.8 critical | 7.1% | 2019-09-18 |
| CVE-2016-9684 EXP | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative i… | Patch early | 9.8 critical | 7.1% | 2017-02-22 |
| CVE-2014-5381 EXP | Grand MA 300 allows a brute-force attack on the PIN. | Patch early | 9.8 critical | 7.1% | 2020-01-13 |
| CVE-2013-7055 EXP | D-Link DIR-100 4.03B07 has PPTP and poe information disclosure | Patch early | 9.8 critical | 7% | 2020-02-04 |
| CVE-2023-37759 EXP | Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an… | Patch early | 9.8 critical | 7% | 2023-09-08 |
| CVE-2017-17097 EXP | gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated reques… | Patch early | 9.8 critical | 6.9% | 2018-01-02 |
| CVE-2025-3605 EXP | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and… | Patch early | 9.8 critical | 6.9% | 2025-05-09 |
| CVE-2015-4683 EXP | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by levera… | Patch early | 9.8 critical | 6.9% | 2017-09-19 |
| CVE-2013-4103 EXP | Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input | Patch early | 9.8 critical | 6.9% | 2019-11-04 |
| CVE-2016-8580 EXP | PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PH… | Patch early | 9.8 critical | 6.9% | 2016-10-28 |
| CVE-2017-2527 EXP | An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimation" component. It allows remot… | Patch early | 9.8 critical | 6.8% | 2017-05-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt