CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,922 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,992 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-2853 | An exploitable Code Execution vulnerability exists in the RequestForPatientInfoEEGfile functionality of Natus Xltek NeuroWorks 8. A specially crafted… | In your normal cycle | 9.8 critical | 3.3% | 2018-04-05 |
| CVE-2020-28872 | An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to creat… | In your normal cycle | 9.8 critical | 3.3% | 2021-04-12 |
| CVE-2023-40748 | PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php. | In your normal cycle | 9.8 critical | 3.3% | 2023-08-28 |
| CVE-2023-0232 | The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to… | In your normal cycle | 9.8 critical | 3.3% | 2023-02-21 |
| CVE-2019-18609 | An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corrupti… | In your normal cycle | 9.8 critical | 3.3% | 2019-12-01 |
| CVE-2019-5079 | An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(1… | In your normal cycle | 9.8 critical | 3.3% | 2019-12-18 |
| CVE-2019-5082 | An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13),… | In your normal cycle | 9.8 critical | 3.3% | 2020-01-08 |
| CVE-2018-8766 | joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.ph… | In your normal cycle | 9.8 critical | 3.3% | 2018-03-18 |
| CVE-2022-29316 | Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch. | In your normal cycle | 9.8 critical | 3.3% | 2022-05-11 |
| CVE-2025-49834 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui… | In your normal cycle | 9.8 critical | 3.3% | 2025-07-15 |
| CVE-2025-49836 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui… | In your normal cycle | 9.8 critical | 3.3% | 2025-07-15 |
| CVE-2019-19015 | An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) allows connections to the interna… | In your normal cycle | 9.8 critical | 3.3% | 2019-12-02 |
| CVE-2023-5991 | The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and au… | In your normal cycle | 9.8 critical | 3.3% | 2023-12-26 |
| CVE-2021-44738 | Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter. | In your normal cycle | 9.8 critical | 3.3% | 2022-01-20 |
| CVE-2020-24208 | A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication pro… | In your normal cycle | 9.8 critical | 3.3% | 2020-08-17 |
| CVE-2019-8071 | Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation. | In your normal cycle | 9.8 critical | 3.3% | 2019-10-17 |
| CVE-2014-2228 | The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages. | In your normal cycle | 9.8 critical | 3.3% | 2020-02-19 |
| CVE-2020-15150 | There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to t… | In your normal cycle | 9.0 critical | 3.3% | 2020-09-01 |
| CVE-2021-36547 | A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary command… | In your normal cycle | 9.8 critical | 3.3% | 2021-10-28 |
| CVE-2021-36548 | A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows at… | In your normal cycle | 9.8 critical | 3.3% | 2021-10-28 |
| CVE-2013-4366 | http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows at… | In your normal cycle | 9.8 critical | 3.3% | 2017-10-30 |
| CVE-2019-6991 | A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an u… | In your normal cycle | 9.8 critical | 3.3% | 2019-01-28 |
| CVE-2020-8803 | SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list. | In your normal cycle | 9.8 critical | 3.3% | 2020-02-13 |
| CVE-2026-25244 | WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 conta… | In your normal cycle | 9.8 critical | 3.3% | 2026-05-18 |
| CVE-2022-46421 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Pr… | In your normal cycle | 9.8 critical | 3.3% | 2022-12-20 |
| CVE-2021-30678 | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Upd… | In your normal cycle | 9.8 critical | 3.3% | 2021-09-08 |
| CVE-2017-17499 | ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cpp. | In your normal cycle | 9.8 critical | 3.3% | 2017-12-11 |
| CVE-2023-42789 | A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0… | In your normal cycle | 9.8 critical | 3.3% | 2024-03-12 |
| CVE-2026-26833 | thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is co… | In your normal cycle | 9.8 critical | 3.3% | 2026-03-25 |
| CVE-2026-60121 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers… | In your normal cycle | 9.8 critical | 3.3% | 2026-07-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt