CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,587 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,457 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-6622 EXP | A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authenticati… | Patch early | 9.8 critical | 62.2% | 2017-05-18 |
| CVE-2022-24223 EXP | AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php. | Patch early | 9.8 critical | 62% | 2022-02-01 |
| CVE-2016-1209 EXP | The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in… | Patch early | 9.8 critical | 61.6% | 2016-05-14 |
| CVE-2017-8835 EXP | SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7… | Patch early | 9.8 critical | 61.6% | 2017-06-05 |
| CVE-2018-16836 EXP | Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbit… | Patch early | 9.8 critical | 61.4% | 2018-09-11 |
| CVE-2018-6329 EXP | It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote at… | Patch early | 9.8 critical | 61.2% | 2018-03-14 |
| CVE-2017-5941 EXP | An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to ach… | Patch early | 9.8 critical | 61% | 2017-02-09 |
| CVE-2019-7304 EXP | Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issu… | Patch early | 9.8 critical | 60.8% | 2019-04-23 |
| CVE-2018-7756 EXP | RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remot… | Patch early | 9.8 critical | 60.7% | 2018-03-15 |
| CVE-2017-15222 EXP | Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code. | Patch early | 9.8 critical | 60.3% | 2017-10-24 |
| CVE-2021-24499 EXP | The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks,… | Patch early | 9.8 critical | 60.1% | 2021-08-09 |
| CVE-2012-2576 EXP | SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWi… | Patch early | 9.8 critical | 59.4% | 2017-12-20 |
| CVE-2019-5485 EXP | NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository na… | Patch early | 10.0 critical | 58.8% | 2019-09-13 |
| CVE-2019-14931 EXP | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote… | Patch early | 9.8 critical | 58.1% | 2019-10-28 |
| CVE-2008-0081 EXP | Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to… | Patch early | 9.8 critical | 57.9% | 2008-01-16 |
| CVE-2018-7314 EXP | SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. | Patch early | 9.8 critical | 57.8% | 2018-02-22 |
| CVE-2018-6605 EXP | SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHov… | Patch early | 9.8 critical | 57.7% | 2018-02-05 |
| CVE-2016-8582 EXP | A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve da… | Patch early | 9.8 critical | 57.4% | 2016-10-28 |
| CVE-2017-6526 EXP | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected admi… | Patch early | 9.8 critical | 57.4% | 2017-03-09 |
| CVE-2020-15922 EXP | There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) pr… | Patch early | 9.8 critical | 57.3% | 2020-07-24 |
| CVE-2019-5029 EXP | An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands s… | Patch early | 9.8 critical | 57.2% | 2019-11-13 |
| CVE-2019-5434 EXP | An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in t… | Patch early | 9.8 critical | 57% | 2019-05-06 |
| CVE-2021-45428 EXP | TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HT… | Patch early | 9.8 critical | 56.9% | 2022-01-03 |
| CVE-2017-6361 EXP | QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors. | Patch early | 9.8 critical | 56.8% | 2017-03-23 |
| CVE-2018-12634 EXP | CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html… | Patch early | 9.8 critical | 56.4% | 2018-06-22 |
| CVE-2018-17173 EXP | LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. | Patch early | 9.8 critical | 56.2% | 2018-09-21 |
| CVE-2016-3078 EXP | Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffe… | Patch early | 9.8 critical | 56.1% | 2016-08-07 |
| CVE-2011-4908 EXP | TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php. | Patch early | 9.8 critical | 55.8% | 2020-02-12 |
| CVE-2019-8387 EXP | MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. | Patch early | 9.8 critical | 55.7% | 2019-05-08 |
| CVE-2014-7236 EXP | Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenablep… | Patch early | 9.1 critical | 55.6% | 2020-02-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt