CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,596 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,458 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-58434 EXP | Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint… | Patch early | 9.8 critical | 49.9% | 2025-09-12 |
| CVE-2016-6909 EXP | Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 a… | Patch early | 9.8 critical | 49.9% | 2016-08-24 |
| CVE-2022-37109 EXP | patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the passwo… | Patch early | 9.8 critical | 49.5% | 2022-11-14 |
| CVE-2018-13862 EXP | Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attackers to reset the authentication… | Patch early | 9.8 critical | 49.3% | 2018-07-17 |
| CVE-2023-3710 EXP | Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 v… | Patch early | 9.9 critical | 49% | 2023-09-12 |
| CVE-2018-9126 EXP | The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credent… | Patch early | 9.8 critical | 48.9% | 2018-04-04 |
| CVE-2013-2568 EXP | A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a re… | Patch early | 9.8 critical | 48.5% | 2020-01-29 |
| CVE-2017-9232 EXP | Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege… | Patch early | 9.8 critical | 48.5% | 2017-05-28 |
| CVE-2020-5377 EXP | Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote atta… | Patch early | 9.1 critical | 48.3% | 2020-07-28 |
| CVE-2018-8096 EXP | Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","V… | Patch early | 9.8 critical | 48.2% | 2018-03-14 |
| CVE-2021-27964 EXP | SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFil… | Patch early | 9.8 critical | 47.5% | 2021-03-05 |
| CVE-2018-5767 EXP | An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with… | Patch early | 9.8 critical | 47.4% | 2018-02-15 |
| CVE-2015-6834 EXP | Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary… | Patch early | 9.8 critical | 46.8% | 2016-05-16 |
| CVE-2019-9879 EXP | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are all… | Patch early | 9.8 critical | 46.6% | 2019-06-10 |
| CVE-2025-29306 EXP | An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component. | Patch early | 9.8 critical | 46.6% | 2025-03-27 |
| CVE-2023-30145 EXP | Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. | Patch early | 9.8 critical | 46.1% | 2023-05-26 |
| CVE-2015-9323 EXP | The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection. | Patch early | 9.8 critical | 46.1% | 2019-08-16 |
| CVE-2022-35411 EXP | rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, althou… | Patch early | 9.8 critical | 45.7% | 2022-07-08 |
| CVE-2019-6444 EXP | An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data… | Patch early | 9.1 critical | 45.7% | 2019-01-16 |
| CVE-2016-1606 EXP | Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code v… | Patch early | 9.8 critical | 45.6% | 2016-07-03 |
| CVE-2021-29003 EXP | Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as… | Patch early | 9.8 critical | 45.4% | 2021-04-13 |
| CVE-2018-15839 EXP | D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header. | Patch early | 9.8 critical | 45.3% | 2018-08-28 |
| CVE-2020-35313 EXP | A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attack… | Patch early | 9.8 critical | 45.2% | 2021-04-20 |
| CVE-2024-48760 EXP | An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlc… | Patch early | 9.8 critical | 45.1% | 2025-01-14 |
| CVE-2024-42640 EXP | angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allow… | Patch early | 9.8 critical | 45.1% | 2024-10-11 |
| CVE-2022-0332 EXP | A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching u… | Patch early | 9.8 critical | 44.9% | 2022-01-25 |
| CVE-2019-8341 EXP | An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" paramet… | Patch early | 9.8 critical | 44.8% | 2019-02-15 |
| CVE-2018-11510 EXP | The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by… | Patch early | 9.8 critical | 44.3% | 2018-06-28 |
| CVE-2020-36847 EXP | The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which… | Patch early | 9.8 critical | 44.2% | 2025-07-12 |
| CVE-2020-13693 EXP | An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled. | Patch early | 9.8 critical | 43.9% | 2020-05-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt