CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,483 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-23488 EXP | The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of t… | Patch early | 9.8 critical | 92.5% | 2023-01-20 |
| CVE-2017-12629 EXP | Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-lis… | Patch early | 9.8 critical | 91.9% | 2017-10-14 |
| CVE-2022-31814 EXP | pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header… | Patch early | 9.8 critical | 91.9% | 2022-09-05 |
| CVE-2018-10933 EXP | A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without firs… | Patch early | 9.1 critical | 91.8% | 2018-10-17 |
| CVE-2014-8739 EXP | Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solu… | Patch early | 9.8 critical | 91.7% | 2020-02-08 |
| CVE-2018-3810 EXP | Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to inser… | Patch early | 9.8 critical | 91.1% | 2018-01-01 |
| CVE-2016-6600 EXP | Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and exec… | Patch early | 9.8 critical | 90.6% | 2017-01-23 |
| CVE-2018-1207 EXP | Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthe… | Patch early | 9.8 critical | 90.1% | 2018-03-23 |
| CVE-2019-12725 EXP | Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTT… | Patch early | 9.8 critical | 89.8% | 2019-07-19 |
| CVE-2019-5420 EXP | A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated deve… | Patch early | 9.8 critical | 89.7% | 2019-03-27 |
| CVE-2018-14417 EXP | A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not… | Patch early | 9.8 critical | 89.6% | 2018-08-04 |
| CVE-2011-3923 EXP | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. | Patch early | 9.8 critical | 89.5% | 2019-11-01 |
| CVE-2013-1359 EXP | An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Ma… | Patch early | 9.8 critical | 89.4% | 2020-02-11 |
| CVE-2018-15708 EXP | Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request. | Patch early | 9.8 critical | 89.4% | 2018-11-14 |
| CVE-2020-8794 EXP | OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this… | Patch early | 9.8 critical | 88.9% | 2020-02-25 |
| CVE-2019-2729 EXP | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected a… | Patch early | 9.8 critical | 88.8% | 2019-06-19 |
| CVE-2024-25600 EXP | Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bric… | Patch early | 10.0 critical | 88.2% | 2024-06-04 |
| CVE-2021-20837 EXP | Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and… | Patch early | 9.8 critical | 88.1% | 2021-10-26 |
| CVE-2020-35729 EXP | KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter. | Patch early | 9.8 critical | 88.1% | 2020-12-27 |
| CVE-2017-17411 EXP | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to e… | Patch early | 9.8 critical | 87.9% | 2017-12-21 |
| CVE-2018-7584 EXP | In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an H… | Patch early | 9.8 critical | 87.3% | 2018-03-01 |
| CVE-2021-32305 EXP | WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter. | Patch early | 9.8 critical | 87.3% | 2021-05-18 |
| CVE-2009-3555 EXP | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache H… | Patch early | 9.8 critical | 87.3% | 2009-11-09 |
| CVE-2018-5999 EXP | An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests conti… | Patch early | 9.8 critical | 87.3% | 2018-01-22 |
| CVE-2017-12611 EXP | In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can l… | Patch early | 9.8 critical | 87.1% | 2017-09-20 |
| CVE-2016-6603 EXP | ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header. | Patch early | 9.8 critical | 87% | 2017-01-23 |
| CVE-2025-32429 EXP | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0… | Patch early | 9.8 critical | 87% | 2025-07-24 |
| CVE-2018-1002105 EXP | In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apis… | Patch early | 9.8 critical | 87% | 2018-12-05 |
| CVE-2021-24762 EXP | The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the… | Patch early | 9.8 critical | 86.8% | 2022-02-01 |
| CVE-2018-0101 EXP | A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthentic… | Patch early | 10.0 critical | 86.8% | 2018-01-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt