CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,185 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-8529 | A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TF… | Patch early | 9.8 critical | 13.5% | 2018-11-15 |
| CVE-2023-27855 | In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote at… | Patch early | 9.8 critical | 13.5% | 2023-03-22 |
| CVE-2022-0867 | The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQ… | Patch early | 9.8 critical | 13.5% | 2022-05-16 |
| CVE-2019-1072 | A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps… | Patch early | 9.8 critical | 13.4% | 2019-07-15 |
| CVE-2010-4239 | Tiki Wiki CMS Groupware 5.2 has Local File Inclusion | Patch early | 9.8 critical | 13.4% | 2019-10-28 |
| CVE-2016-5841 | Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or po… | Patch early | 9.8 critical | 13.4% | 2016-12-13 |
| CVE-2024-1873 | parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0.… | Patch early | 9.1 critical | 13.4% | 2024-06-06 |
| CVE-2020-4469 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HT… | Patch early | 9.8 critical | 13.4% | 2020-06-15 |
| CVE-2021-34371 | Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVariab… | Patch early | 9.8 critical | 13.4% | 2021-08-05 |
| CVE-2017-0252 | A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scrip… | Patch early | 9.8 critical | 13.4% | 2017-05-15 |
| CVE-2021-44352 | A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetI… | Patch early | 9.8 critical | 13.4% | 2021-12-03 |
| CVE-2019-9960 | The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path. | Patch early | 9.8 critical | 13.4% | 2019-03-24 |
| CVE-2019-11944 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | Patch early | 9.8 critical | 13.3% | 2019-06-05 |
| CVE-2016-0718 | Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which… | Patch early | 9.8 critical | 13.3% | 2016-05-26 |
| CVE-2018-4987 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Untrusted pointer der… | Patch early | 9.8 critical | 13.3% | 2018-07-09 |
| CVE-2015-9263 | An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbit… | Patch early | 9.8 critical | 13.3% | 2018-08-27 |
| CVE-2023-43237 | D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC. | Patch early | 9.8 critical | 13.3% | 2023-09-21 |
| CVE-2023-43239 | D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC. | Patch early | 9.8 critical | 13.3% | 2023-09-21 |
| CVE-2023-43240 | D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter. | Patch early | 9.8 critical | 13.3% | 2023-09-21 |
| CVE-2025-36038 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence o… | Patch early | 9.0 critical | 13.3% | 2025-06-25 |
| CVE-2018-12798 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerab… | Patch early | 9.8 critical | 13.3% | 2018-07-20 |
| CVE-2019-8985 | On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that d… | Patch early | 9.8 critical | 13.3% | 2019-02-21 |
| CVE-2023-44693 | D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php. | Patch early | 9.8 critical | 13.3% | 2023-10-17 |
| CVE-2025-0105 | An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to… | Patch early | 9.1 critical | 13.3% | 2025-01-11 |
| CVE-2025-49212 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on… | Patch early | 9.8 critical | 13.3% | 2025-06-17 |
| CVE-2025-49213 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on… | Patch early | 9.8 critical | 13.3% | 2025-06-17 |
| CVE-2021-31316 | The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter. | Patch early | 9.8 critical | 13.3% | 2021-05-18 |
| CVE-2022-0786 | The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX act… | Patch early | 9.8 critical | 13.3% | 2022-06-13 |
| CVE-2016-3642 | The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized… | Patch early | 9.8 critical | 13.3% | 2016-06-17 |
| CVE-2021-21986 | The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lif… | Patch early | 9.8 critical | 13.3% | 2021-05-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt