CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,587 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,457 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-10594 EXP | Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS… | Patch early | 9.8 critical | 68.6% | 2018-06-26 |
| CVE-2016-6195 EXP | SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remot… | Patch early | 9.8 critical | 68.5% | 2016-08-30 |
| CVE-2024-28000 EXP | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a th… | Patch early | 9.8 critical | 68.3% | 2024-08-21 |
| CVE-2017-12477 EXP | It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its… | Patch early | 9.8 critical | 68.2% | 2017-08-07 |
| CVE-2012-5357 EXP | Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attacker… | Patch early | 9.8 critical | 67.8% | 2017-10-30 |
| CVE-2016-6662 EXP | Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17;… | Patch early | 9.8 critical | 67.7% | 2016-09-20 |
| CVE-2020-0610 EXP | A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target sy… | Patch early | 9.8 critical | 67.6% | 2020-01-14 |
| CVE-2026-23744 EXP | MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vul… | Patch early | 9.8 critical | 67.5% | 2026-01-16 |
| CVE-2012-0694 EXP | SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code. | Patch early | 9.8 critical | 67.3% | 2019-10-29 |
| CVE-2019-13101 EXP | An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead… | Patch early | 9.8 critical | 67.1% | 2019-08-08 |
| CVE-2019-6443 EXP | An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_contro… | Patch early | 9.1 critical | 66.9% | 2019-01-16 |
| CVE-2017-11394 EXP | Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable install… | Patch early | 9.8 critical | 66.8% | 2017-08-03 |
| CVE-2021-32172 EXP | Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin. | Patch early | 9.8 critical | 66.4% | 2021-10-07 |
| CVE-2021-37425 EXP | Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobil… | Patch early | 9.1 critical | 66.3% | 2021-08-10 |
| CVE-2012-2926 EXP | Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, a… | Patch early | 9.1 critical | 66.3% | 2012-05-22 |
| CVE-2017-6360 EXP | QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors. | Patch early | 9.8 critical | 66.1% | 2017-03-23 |
| CVE-2025-55315 EXP | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security fe… | Patch early | 9.9 critical | 65.9% | 2025-10-14 |
| CVE-2019-10123 EXP | SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker t… | Patch early | 9.8 critical | 65.9% | 2019-05-31 |
| CVE-2017-14147 EXP | An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its f… | Patch early | 9.8 critical | 65.6% | 2017-09-07 |
| CVE-2016-10175 EXP | The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user… | Patch early | 9.8 critical | 65% | 2017-01-30 |
| CVE-2020-7115 EXP | The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker coul… | Patch early | 9.8 critical | 64.6% | 2020-06-03 |
| CVE-2018-6328 EXP | It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unaut… | Patch early | 9.8 critical | 64.4% | 2018-03-14 |
| CVE-2016-2296 EXP | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attack… | Patch early | 9.4 critical | 64.3% | 2016-05-14 |
| CVE-2018-7297 EXP | Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access a… | Patch early | 9.8 critical | 64.3% | 2018-02-22 |
| CVE-2017-9417 EXP | Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue. | Patch early | 9.8 critical | 64% | 2017-06-04 |
| CVE-2017-11165 EXP | dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /service… | Patch early | 9.8 critical | 63.9% | 2017-07-12 |
| CVE-2018-16283 EXP | The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. | Patch early | 9.8 critical | 63.1% | 2018-09-24 |
| CVE-2012-0911 EXP | TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1)… | Patch early | 9.8 critical | 63% | 2012-07-12 |
| CVE-2026-0740 EXP | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Con… | Patch early | 9.8 critical | 62.9% | 2026-04-07 |
| CVE-2024-8522 EXP | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress… | Patch early | 10.0 critical | 62.9% | 2024-09-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt