CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,648 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-10653 EXP | There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | Patch early | 9.8 critical | 6.8% | 2018-05-23 |
| CVE-2026-34156 EXP | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's W… | Patch early | 9.9 critical | 6.8% | 2026-03-31 |
| CVE-2017-2524 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | Patch early | 9.8 critical | 6.7% | 2017-05-22 |
| CVE-2017-7237 EXP | The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directo… | Patch early | 9.8 critical | 6.7% | 2017-04-06 |
| CVE-2010-1866 EXP | The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of se… | Patch early | 9.8 critical | 6.7% | 2010-05-07 |
| CVE-2022-23366 EXP | HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php. | Patch early | 9.8 critical | 6.7% | 2022-01-21 |
| CVE-2017-17098 EXP | The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary P… | Patch early | 9.8 critical | 6.6% | 2018-01-02 |
| CVE-2019-0285 EXP | The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including creden… | Patch early | 9.8 critical | 6.6% | 2019-04-10 |
| CVE-2017-2522 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | Patch early | 9.8 critical | 6.6% | 2017-05-22 |
| CVE-2015-8282 EXP | SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account. | Patch early | 9.8 critical | 6.6% | 2017-04-13 |
| CVE-2017-7175 EXP | NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom outpu… | Patch early | 9.9 critical | 6.5% | 2017-07-10 |
| CVE-2018-4367 EXP | A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1. | Patch early | 9.8 critical | 6.5% | 2019-04-03 |
| CVE-2023-0744 EXP | Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4. | Patch early | 9.8 critical | 6.4% | 2023-02-08 |
| CVE-2021-45814 EXP | Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account… | Patch early | 9.8 critical | 6.3% | 2021-12-28 |
| CVE-2020-14944 EXP | Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeov… | Patch early | 9.8 critical | 6.3% | 2020-06-22 |
| CVE-2013-4864 EXP | MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/prox… | Patch early | 9.8 critical | 6.3% | 2020-01-28 |
| CVE-2017-5344 EXP | An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet per… | Patch early | 9.8 critical | 6.3% | 2017-02-17 |
| CVE-2019-8352 EXP | By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed… | Patch early | 9.8 critical | 6.3% | 2019-05-20 |
| CVE-2015-4594 EXP | eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a n… | Patch early | 9.8 critical | 6.2% | 2017-01-10 |
| CVE-2018-7474 EXP | An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php. | Patch early | 9.8 critical | 6.2% | 2018-03-14 |
| CVE-2019-10866 EXP | In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-ma… | Patch early | 9.8 critical | 6.2% | 2019-05-23 |
| CVE-2026-25895 EXP | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote att… | Patch early | 9.8 critical | 6.2% | 2026-02-09 |
| CVE-2009-2382 EXP | admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin co… | Patch early | 9.8 critical | 6.2% | 2009-07-08 |
| CVE-2021-43650 EXP | WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process. | Patch early | 9.8 critical | 6.2% | 2022-03-22 |
| CVE-2020-7750 EXP | This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can… | Patch early | 9.6 critical | 6.1% | 2020-10-21 |
| CVE-2015-4633 EXP | Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1)… | Patch early | 9.8 critical | 6.1% | 2018-10-18 |
| CVE-2023-26918 EXP | Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as… | Patch early | 9.8 critical | 6.1% | 2023-04-14 |
| CVE-2017-16716 EXP | A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands. | Patch early | 9.8 critical | 6% | 2018-01-05 |
| CVE-2021-44655 EXP | Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can… | Patch early | 9.8 critical | 6% | 2021-12-15 |
| CVE-2021-44653 EXP | Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due… | Patch early | 9.8 critical | 6% | 2021-12-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt