CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,553 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
36,454 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-30258 EXP | Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP… | Patch early | 9.8 critical | 94.3% | 2023-06-23 |
| CVE-2016-1524 EXP | Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary… | Patch early | 9.6 critical | 94.1% | 2016-02-13 |
| CVE-2024-8856 EXP | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the… | Patch early | 9.8 critical | 94% | 2024-11-16 |
| CVE-2020-17506 EXP | Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injectio… | Patch early | 9.8 critical | 94% | 2020-08-12 |
| CVE-2018-6892 EXP | An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listeni… | Patch early | 9.8 critical | 93.4% | 2018-02-11 |
| CVE-2019-7276 EXP | Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console. | Patch early | 9.8 critical | 93.4% | 2019-07-01 |
| CVE-2017-14492 EXP | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted… | Patch early | 9.8 critical | 93.3% | 2017-10-03 |
| CVE-2016-4010 EXP | Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialize… | Patch early | 9.8 critical | 92.9% | 2017-01-23 |
| CVE-2019-15976 EXP | Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker… | Patch early | 9.8 critical | 92.8% | 2020-01-06 |
| CVE-2022-21907 EXP | HTTP Protocol Stack Remote Code Execution Vulnerability | Patch early | 9.8 critical | 92.8% | 2022-01-11 |
| CVE-2023-23488 EXP | The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of t… | Patch early | 9.8 critical | 92.5% | 2023-01-20 |
| CVE-2017-12629 EXP | Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-lis… | Patch early | 9.8 critical | 91.9% | 2017-10-14 |
| CVE-2022-31814 EXP | pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header… | Patch early | 9.8 critical | 91.9% | 2022-09-05 |
| CVE-2018-10933 EXP | A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without firs… | Patch early | 9.1 critical | 91.8% | 2018-10-17 |
| CVE-2014-8739 EXP | Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solu… | Patch early | 9.8 critical | 91.7% | 2020-02-08 |
| CVE-2018-3810 EXP | Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to inser… | Patch early | 9.8 critical | 91.1% | 2018-01-01 |
| CVE-2016-6600 EXP | Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and exec… | Patch early | 9.8 critical | 90.6% | 2017-01-23 |
| CVE-2018-1207 EXP | Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthe… | Patch early | 9.8 critical | 90.1% | 2018-03-23 |
| CVE-2019-12725 EXP | Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTT… | Patch early | 9.8 critical | 89.8% | 2019-07-19 |
| CVE-2019-5420 EXP | A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated deve… | Patch early | 9.8 critical | 89.7% | 2019-03-27 |
| CVE-2018-14417 EXP | A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not… | Patch early | 9.8 critical | 89.6% | 2018-08-04 |
| CVE-2011-3923 EXP | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. | Patch early | 9.8 critical | 89.5% | 2019-11-01 |
| CVE-2013-1359 EXP | An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Ma… | Patch early | 9.8 critical | 89.4% | 2020-02-11 |
| CVE-2018-15708 EXP | Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request. | Patch early | 9.8 critical | 89.4% | 2018-11-14 |
| CVE-2020-8794 EXP | OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this… | Patch early | 9.8 critical | 88.9% | 2020-02-25 |
| CVE-2019-2729 EXP | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected a… | Patch early | 9.8 critical | 88.8% | 2019-06-19 |
| CVE-2024-25600 EXP | Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bric… | Patch early | 10.0 critical | 88.2% | 2024-06-04 |
| CVE-2021-20837 EXP | Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and… | Patch early | 9.8 critical | 88.1% | 2021-10-26 |
| CVE-2020-35729 EXP | KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter. | Patch early | 9.8 critical | 88.1% | 2020-12-27 |
| CVE-2017-17411 EXP | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to e… | Patch early | 9.8 critical | 87.9% | 2017-12-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt