CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,587 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,458 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-43857 EXP | Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched… | Patch early | 9.8 critical | 55.3% | 2021-12-27 |
| CVE-2016-6602 EXP | ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartex… | Patch early | 9.8 critical | 55.1% | 2017-01-23 |
| CVE-2022-36267 EXP | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can… | Patch early | 9.8 critical | 54.5% | 2022-08-08 |
| CVE-2022-24562 EXP | In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the enti… | Patch early | 9.8 critical | 54.5% | 2022-06-16 |
| CVE-2024-11972 EXP | The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install an… | Patch early | 9.8 critical | 54.5% | 2024-12-31 |
| CVE-2025-49132 EXP | Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespac… | Patch early | 10.0 critical | 54.5% | 2025-06-20 |
| CVE-2021-36356 EXP | KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary e… | Patch early | 9.8 critical | 54.4% | 2021-08-31 |
| CVE-2018-5347 EXP | Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because… | Patch early | 9.8 critical | 54.2% | 2018-01-12 |
| CVE-2025-27007 EXP | Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a… | Patch early | 9.8 critical | 53.9% | 2025-05-01 |
| CVE-2018-8734 EXP | SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL comm… | Patch early | 9.8 critical | 53.8% | 2018-04-18 |
| CVE-2019-6441 EXP | An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The passw… | Patch early | 9.8 critical | 53.6% | 2019-03-21 |
| CVE-2017-17932 EXP | A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute ar… | Patch early | 9.8 critical | 53.6% | 2017-12-28 |
| CVE-2023-27823 EXP | An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. | Patch early | 9.8 critical | 53.6% | 2023-05-12 |
| CVE-2019-19844 EXP | Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing… | Patch early | 9.8 critical | 53.6% | 2019-12-18 |
| CVE-2023-29689 EXP | PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vuln… | Patch early | 9.8 critical | 53.5% | 2023-08-04 |
| CVE-2018-7739 EXP | antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demons… | Patch early | 9.8 critical | 53.2% | 2018-03-07 |
| CVE-2019-9760 EXP | FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-controlled machine that sends craf… | Patch early | 9.8 critical | 53.1% | 2019-03-14 |
| CVE-2018-8021 EXP | Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. N… | Patch early | 9.8 critical | 52.8% | 2018-11-07 |
| CVE-2022-31126 EXP | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauth… | Patch early | 10.0 critical | 52.6% | 2022-07-06 |
| CVE-2018-11686 EXP | The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. | Patch early | 9.8 critical | 52.5% | 2019-07-03 |
| CVE-2017-5174 EXP | An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has bee… | Patch early | 9.8 critical | 52.3% | 2017-05-19 |
| CVE-2016-2345 EXP | Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbit… | Patch early | 9.8 critical | 51.2% | 2016-03-17 |
| CVE-2018-1217 EXP | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affec… | Patch early | 9.8 critical | 50.9% | 2018-04-09 |
| CVE-2021-34646 EXP | Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_ve… | Patch early | 9.8 critical | 50.9% | 2021-08-30 |
| CVE-2019-12518 EXP | Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability. | Patch early | 9.8 critical | 50.7% | 2019-12-02 |
| CVE-2024-25735 EXP | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config… | Patch early | 9.1 critical | 50.6% | 2024-03-27 |
| CVE-2018-19524 EXP | An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 dev… | Patch early | 9.8 critical | 50.5% | 2019-03-21 |
| CVE-2017-16720 EXP | A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the t… | Patch early | 9.8 critical | 50.3% | 2018-01-05 |
| CVE-2017-6465 EXP | Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; howeve… | Patch early | 9.8 critical | 50.3% | 2017-03-10 |
| CVE-2012-3363 EXP | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attac… | Patch early | 9.1 critical | 50.2% | 2013-02-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt