CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,483 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-8869 EXP | The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers… | Patch early | 9.8 critical | 97.3% | 2016-11-04 |
| CVE-2020-11455 EXP | LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php. | Patch early | 9.8 critical | 97.2% | 2020-04-01 |
| CVE-2016-9299 EXP | The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java objec… | Patch early | 9.8 critical | 96.9% | 2017-01-12 |
| CVE-2021-44790 EXP | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd… | Patch early | 9.8 critical | 96.8% | 2021-12-20 |
| CVE-2019-17662 EXP | ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication i… | Patch early | 9.8 critical | 96.8% | 2019-10-16 |
| CVE-2019-9194 EXP | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. | Patch early | 9.8 critical | 96.7% | 2019-02-26 |
| CVE-2020-3187 EXP | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co… | Patch early | 9.1 critical | 96.6% | 2020-05-06 |
| CVE-2019-15975 EXP | Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker… | Patch early | 9.8 critical | 96.5% | 2020-01-06 |
| CVE-2011-2523 EXP | vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp. | Patch early | 9.8 critical | 96.2% | 2019-11-27 |
| CVE-2022-36446 EXP | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command. | Patch early | 9.8 critical | 96% | 2022-07-25 |
| CVE-2023-0297 EXP | Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31. | Patch early | 9.8 critical | 95.9% | 2023-01-14 |
| CVE-2019-1663 EXP | A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, a… | Patch early | 9.8 critical | 95.7% | 2019-02-28 |
| CVE-2020-11530 EXP | A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied… | Patch early | 9.8 critical | 95.7% | 2020-05-08 |
| CVE-2021-22911 EXP | A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulti… | Patch early | 9.8 critical | 95.2% | 2021-05-27 |
| CVE-2024-0204 EXP | Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal. | Patch early | 9.8 critical | 95.1% | 2024-01-22 |
| CVE-2020-24186 EXP | A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to up… | Patch early | 10.0 critical | 94.6% | 2020-08-24 |
| CVE-2016-5674 EXP | __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 throu… | Patch early | 9.8 critical | 94.6% | 2016-08-31 |
| CVE-2021-46422 EXP | Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authe… | Patch early | 9.8 critical | 94.3% | 2022-04-27 |
| CVE-2018-3245 EXP | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… | Patch early | 9.8 critical | 94.3% | 2018-10-17 |
| CVE-2016-2004 EXP | HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors rela… | Patch early | 9.8 critical | 94.3% | 2016-04-21 |
| CVE-2023-30258 EXP | Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP… | Patch early | 9.8 critical | 94.3% | 2023-06-23 |
| CVE-2016-1524 EXP | Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary… | Patch early | 9.6 critical | 94.1% | 2016-02-13 |
| CVE-2024-8856 EXP | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the… | Patch early | 9.8 critical | 94% | 2024-11-16 |
| CVE-2020-17506 EXP | Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injectio… | Patch early | 9.8 critical | 94% | 2020-08-12 |
| CVE-2018-6892 EXP | An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listeni… | Patch early | 9.8 critical | 93.4% | 2018-02-11 |
| CVE-2019-7276 EXP | Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console. | Patch early | 9.8 critical | 93.4% | 2019-07-01 |
| CVE-2017-14492 EXP | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted… | Patch early | 9.8 critical | 93.3% | 2017-10-03 |
| CVE-2016-4010 EXP | Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialize… | Patch early | 9.8 critical | 92.9% | 2017-01-23 |
| CVE-2019-15976 EXP | Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker… | Patch early | 9.8 critical | 92.8% | 2020-01-06 |
| CVE-2022-21907 EXP | HTTP Protocol Stack Remote Code Execution Vulnerability | Patch early | 9.8 critical | 92.8% | 2022-01-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt