CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,482 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-9198 KEV EXP | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with… | Patch first | 9.8 critical | 28.7% | 2026-07-17 |
| CVE-2026-33017 KEV EXP | Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}… | Patch first | 9.8 critical | 24.8% | 2026-03-20 |
| CVE-2025-24085 KEV EXP | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15… | Patch first | 10.0 critical | 17.5% | 2025-01-27 |
| CVE-2026-48907 KEV EXP | A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in P… | Patch first | 9.8 critical | 16.2% | 2026-06-05 |
| CVE-2026-9082 KEV EXP | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This i… | Patch first | 9.8 critical | 15.7% | 2026-05-20 |
| CVE-2022-42889 EXP | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolati… | Patch early | 9.8 critical | 99.9% | 2022-10-13 |
| CVE-2017-12635 EXP | Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.… | Patch early | 9.8 critical | 99.8% | 2017-11-14 |
| CVE-2017-8917 EXP | SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors. | Patch early | 9.8 critical | 99.8% | 2017-05-17 |
| CVE-2020-10220 EXP | An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter. | Patch early | 9.8 critical | 99.7% | 2020-03-07 |
| CVE-2023-27372 EXP | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,… | Patch early | 9.8 critical | 99.7% | 2023-02-28 |
| CVE-2022-37061 EXP | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject an… | Patch early | 9.8 critical | 99.6% | 2022-08-18 |
| CVE-2023-32560 EXP | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code executi… | Patch early | 9.8 critical | 99.4% | 2023-08-10 |
| CVE-2025-1974 EXP | A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve a… | Patch early | 9.8 critical | 99.4% | 2025-03-25 |
| CVE-2017-12542 EXP | A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found. | Patch early | 10.0 critical | 99.3% | 2018-02-15 |
| CVE-2023-23333 EXP | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions throug… | Patch early | 9.8 critical | 99.3% | 2023-02-06 |
| CVE-2025-29927 EXP | Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 1… | Patch early | 9.1 critical | 99.2% | 2025-03-21 |
| CVE-2022-24637 EXP | Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin… | Patch early | 9.8 critical | 99.1% | 2022-03-18 |
| CVE-2020-7209 EXP | LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2. | Patch early | 9.8 critical | 98.8% | 2020-02-13 |
| CVE-2018-19276 EXP | OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary command… | Patch early | 9.8 critical | 98.7% | 2019-03-21 |
| CVE-2020-15920 EXP | There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (… | Patch early | 9.8 critical | 98.2% | 2020-07-24 |
| CVE-2020-35847 EXP | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function. | Patch early | 9.8 critical | 98.2% | 2020-12-30 |
| CVE-2023-6553 EXP | The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-… | Patch early | 9.8 critical | 97.8% | 2023-12-15 |
| CVE-2016-10045 EXP | The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arb… | Patch early | 9.8 critical | 97.7% | 2016-12-30 |
| CVE-2019-16662 EXP | An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php becau… | Patch early | 9.8 critical | 97.7% | 2019-10-28 |
| CVE-2019-18818 EXP | strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions… | Patch early | 9.8 critical | 97.6% | 2019-11-07 |
| CVE-2021-3378 EXP | FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then… | Patch early | 9.8 critical | 97.5% | 2021-02-01 |
| CVE-2019-0230 EXP | Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. | Patch early | 9.8 critical | 97.4% | 2020-09-14 |
| CVE-2018-17456 EXP | Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code… | Patch early | 9.8 critical | 97.4% | 2018-10-06 |
| CVE-2017-3248 EXP | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affecte… | Patch early | 9.8 critical | 97.3% | 2017-01-27 |
| CVE-2018-9206 EXP | Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0 | Patch early | 9.8 critical | 97.3% | 2018-10-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt