CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,098 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,706 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-5819 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | Patch early | 9.8 critical | 18.2% | 2018-02-15 |
| CVE-2017-5820 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | Patch early | 9.8 critical | 18.2% | 2018-02-15 |
| CVE-2017-5823 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | Patch early | 9.8 critical | 18.2% | 2018-02-15 |
| CVE-2017-8954 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. | Patch early | 9.8 critical | 18.2% | 2018-02-15 |
| CVE-2017-8957 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. | Patch early | 9.8 critical | 18.2% | 2018-02-15 |
| CVE-2017-8975 | A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found. | Patch early | 9.8 critical | 18.2% | 2018-02-15 |
| CVE-2017-8976 | A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found. | Patch early | 9.8 critical | 18.2% | 2018-02-15 |
| CVE-2023-40787 | In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection. | Patch early | 9.8 critical | 18.2% | 2023-08-29 |
| CVE-2023-34993 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.… | Patch early | 9.8 critical | 18.1% | 2023-10-10 |
| CVE-2021-27931 | LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a req… | Patch early | 9.1 critical | 18.1% | 2021-03-03 |
| CVE-2021-41749 | In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowin… | Patch early | 9.8 critical | 18.1% | 2022-06-12 |
| CVE-2022-4120 | The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PH… | Patch early | 9.8 critical | 18.1% | 2022-12-26 |
| CVE-2016-2324 | Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which trigger… | Patch early | 9.8 critical | 18.1% | 2016-04-08 |
| CVE-2025-54987 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and e… | Patch early | 9.4 critical | 18.1% | 2025-08-05 |
| CVE-2021-33055 | Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions. | Patch early | 9.8 critical | 18.1% | 2021-08-30 |
| CVE-2023-46370 | Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function. | Patch early | 9.8 critical | 18.1% | 2023-10-25 |
| CVE-2020-36112 | CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php… | Patch early | 9.8 critical | 18.1% | 2021-01-04 |
| CVE-2021-24867 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins a… | Patch early | 9.8 critical | 18% | 2022-02-21 |
| CVE-2024-54819 | I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/vali… | Patch early | 9.1 critical | 18% | 2025-01-07 |
| CVE-2024-29990 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | Patch early | 9.0 critical | 18% | 2024-04-09 |
| CVE-2017-5790 | A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found. | Patch early | 9.8 critical | 18% | 2018-02-15 |
| CVE-2026-21902 | An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved… | Patch early | 9.8 critical | 18% | 2026-02-25 |
| CVE-2022-30063 | ftcms <=2.1 was discovered to be vulnerable to code execution attacks . | Patch early | 9.8 critical | 18% | 2022-05-11 |
| CVE-2022-35413 | WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential informa… | Patch early | 9.8 critical | 18% | 2022-09-13 |
| CVE-2016-7277 | Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "… | Patch early | 9.6 critical | 18% | 2016-12-20 |
| CVE-2022-38916 | A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files | Patch early | 9.8 critical | 17.9% | 2022-09-20 |
| CVE-2021-40418 | When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property containing… | Patch early | 9.8 critical | 17.9% | 2021-12-22 |
| CVE-2019-5482 | Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3. | Patch early | 9.8 critical | 17.9% | 2019-09-16 |
| CVE-2024-23469 | SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthentic… | Patch early | 9.6 critical | 17.9% | 2024-07-17 |
| CVE-2017-5789 | HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote attackers to execute arbitrary code via unspecified v… | Patch early | 9.8 critical | 17.9% | 2017-10-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt