CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,200 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-54794 | The script input feature of SpagoBI 3.5.1 allows arbitrary code execution. | Patch early | 9.1 critical | 12.8% | 2025-01-21 |
| CVE-2016-10229 | udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calcula… | Patch early | 9.8 critical | 12.8% | 2017-04-04 |
| CVE-2020-24786 | An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus befor… | Patch early | 9.8 critical | 12.8% | 2020-08-31 |
| CVE-2025-28219 | Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via… | Patch early | 9.8 critical | 12.8% | 2025-03-28 |
| CVE-2023-35036 | In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vu… | Patch early | 9.1 critical | 12.8% | 2023-06-12 |
| CVE-2019-20049 | An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to by… | Patch early | 9.8 critical | 12.8% | 2019-12-27 |
| CVE-2018-17179 | An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_func… | Patch early | 9.8 critical | 12.8% | 2019-05-17 |
| CVE-2020-8540 | An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to r… | Patch early | 9.8 critical | 12.8% | 2020-03-11 |
| CVE-2017-6342 | An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and… | Patch early | 9.8 critical | 12.8% | 2017-02-27 |
| CVE-2024-34854 | F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.` | Patch early | 9.8 critical | 12.8% | 2024-05-28 |
| CVE-2023-37791 | D-Link DIR-619L v2.04(TW) was discovered to contain a stack overflow via the curTime parameter at /goform/formLogin. | Patch early | 9.8 critical | 12.7% | 2023-07-17 |
| CVE-2017-7722 | In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password"… | Patch early | 10.0 critical | 12.7% | 2017-04-12 |
| CVE-2021-32099 | A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivilege… | Patch early | 9.8 critical | 12.7% | 2021-05-07 |
| CVE-2021-22658 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator… | Patch early | 9.8 critical | 12.7% | 2021-02-11 |
| CVE-2016-2170 | Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java ob… | Patch early | 9.8 critical | 12.7% | 2016-04-12 |
| CVE-2018-14718 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class… | Patch early | 9.8 critical | 12.7% | 2019-01-02 |
| CVE-2020-15588 | An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overf… | Patch early | 9.8 critical | 12.7% | 2020-07-29 |
| CVE-2025-12762 | pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores… | Patch early | 9.1 critical | 12.7% | 2025-11-13 |
| CVE-2018-18500 | A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object… | Patch early | 9.8 critical | 12.7% | 2019-02-05 |
| CVE-2019-16746 | An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon he… | Patch early | 9.8 critical | 12.7% | 2019-09-24 |
| CVE-2015-5473 | Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary files via unspecified paramet… | Patch early | 9.8 critical | 12.6% | 2017-06-01 |
| CVE-2017-5162 | An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for remote service gives access to ap… | Patch early | 9.8 critical | 12.6% | 2017-02-13 |
| CVE-2020-13640 | A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via th… | Patch early | 9.8 critical | 12.6% | 2020-06-18 |
| CVE-2021-25832 | A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using thi… | Patch early | 9.8 critical | 12.6% | 2021-03-01 |
| CVE-2018-1000226 | Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be v… | Patch early | 9.8 critical | 12.6% | 2018-08-20 |
| CVE-2011-4372 | Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of se… | Patch early | 9.8 critical | 12.6% | 2012-01-10 |
| CVE-2021-24827 | The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL stateme… | Patch early | 9.8 critical | 12.6% | 2021-11-08 |
| CVE-2018-10942 | modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to exec… | Patch early | 9.8 critical | 12.6% | 2018-05-10 |
| CVE-2017-12379 | ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of… | Patch early | 9.8 critical | 12.5% | 2018-01-26 |
| CVE-2025-34035 | An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properl… | Patch early | 9.8 critical | 12.5% | 2025-06-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt