CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,579 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
36,456 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-20526 EXP | Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php. | Patch early | 9.8 critical | 73.1% | 2019-03-21 |
| CVE-2021-24946 EXP | The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in th… | Patch early | 9.8 critical | 72.8% | 2021-12-13 |
| CVE-2017-6326 EXP | The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the abili… | Patch early | 10.0 critical | 72.8% | 2017-06-26 |
| CVE-2014-9618 EXP | The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authenticatio… | Patch early | 9.8 critical | 72.7% | 2017-09-19 |
| CVE-2021-4045 EXP | TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd bina… | Patch early | 9.8 critical | 72.4% | 2022-03-10 |
| CVE-2023-3460 EXP | The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allow… | Patch early | 9.8 critical | 72.3% | 2023-07-04 |
| CVE-2016-1560 EXP | ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support a… | Patch early | 9.8 critical | 72.3% | 2017-04-21 |
| CVE-2019-16724 EXP | File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer… | Patch early | 9.8 critical | 72.2% | 2019-09-24 |
| CVE-2021-40859 EXP | Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application f… | Patch early | 9.8 critical | 72% | 2021-12-07 |
| CVE-2018-7251 EXP | An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL… | Patch early | 9.8 critical | 71.8% | 2018-02-19 |
| CVE-2020-8518 EXP | Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution. | Patch early | 9.8 critical | 71.7% | 2020-02-17 |
| CVE-2014-8684 EXP | CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequen… | Patch early | 9.8 critical | 71.7% | 2017-09-19 |
| CVE-2019-11231 EXP | An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files with arbitrar… | Patch early | 9.8 critical | 71.6% | 2019-05-22 |
| CVE-2018-20434 EXP | LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during… | Patch early | 9.8 critical | 71.5% | 2019-04-24 |
| CVE-2021-46419 EXP | An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts. | Patch early | 9.1 critical | 71.4% | 2022-04-07 |
| CVE-2016-1909 EXP | Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4… | Patch early | 9.8 critical | 71.3% | 2016-01-15 |
| CVE-2021-4039 EXP | A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on t… | Patch early | 9.8 critical | 71% | 2022-03-01 |
| CVE-2020-29597 EXP | IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upl… | Patch early | 9.8 critical | 71% | 2020-12-07 |
| CVE-2017-8895 EXP | In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in… | Patch early | 9.8 critical | 71% | 2017-05-10 |
| CVE-2016-5675 EXP | handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR Ready… | Patch early | 9.8 critical | 70.9% | 2016-08-31 |
| CVE-2021-35064 EXP | KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous comm… | Patch early | 9.8 critical | 70.8% | 2021-07-12 |
| CVE-2018-10094 EXP | SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameter… | Patch early | 9.8 critical | 70.7% | 2018-05-22 |
| CVE-2013-4211 EXP | A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicio… | Patch early | 9.8 critical | 70.7% | 2020-02-14 |
| CVE-2007-3798 EXP | Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs i… | Patch early | 9.8 critical | 70.4% | 2007-07-16 |
| CVE-2019-7257 EXP | Linear eMerge E3-Series devices allow Unrestricted File Upload. | Patch early | 10.0 critical | 70% | 2019-07-02 |
| CVE-2021-42071 EXP | In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/log… | Patch early | 9.8 critical | 69.9% | 2021-10-07 |
| CVE-2012-4284 EXP | A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binar… | Patch early | 9.8 critical | 69.5% | 2020-01-10 |
| CVE-2018-7573 EXP | An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with the FTP 220 response code to cr… | Patch early | 9.8 critical | 69.2% | 2018-03-01 |
| CVE-2021-34621 EXP | A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it p… | Patch early | 9.8 critical | 68.9% | 2021-07-07 |
| CVE-2013-3215 EXP | vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. | Patch early | 9.8 critical | 68.8% | 2020-01-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt