CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,603 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,461 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-9880 EXP | An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacke… | Patch early | 9.1 critical | 34.8% | 2019-06-10 |
| CVE-2019-16451 EXP | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | Patch early | 9.8 critical | 34.7% | 2019-12-19 |
| CVE-2019-8048 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 34.6% | 2019-08-20 |
| CVE-2017-16930 EXP | The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack… | Patch early | 9.8 critical | 34.3% | 2017-12-05 |
| CVE-2017-5792 EXP | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found. | Patch early | 9.8 critical | 34.3% | 2018-02-15 |
| CVE-2016-2563 EXP | Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denia… | Patch early | 9.8 critical | 34.2% | 2016-04-07 |
| CVE-2017-11281 EXP | Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary c… | Patch early | 9.8 critical | 33.9% | 2017-12-01 |
| CVE-2022-37661 EXP | SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature. | Patch early | 9.8 critical | 33.9% | 2022-09-14 |
| CVE-2017-5375 EXP | JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thun… | Patch early | 9.8 critical | 33.8% | 2018-06-11 |
| CVE-2017-5815 EXP | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | Patch early | 9.8 critical | 33.7% | 2018-02-15 |
| CVE-2017-7588 EXP | On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affecte… | Patch early | 9.8 critical | 33.6% | 2017-04-12 |
| CVE-2021-31761 EXP | Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature. | Patch early | 9.6 critical | 33.6% | 2021-04-25 |
| CVE-2017-16885 EXP | Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Chang… | Patch early | 9.8 critical | 33.5% | 2018-01-12 |
| CVE-2018-11094 EXP | An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasic… | Patch early | 9.8 critical | 33.4% | 2018-05-15 |
| CVE-2016-0801 EXP | The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to exe… | Patch early | 9.8 critical | 33.1% | 2016-02-07 |
| CVE-2017-6187 EXP | Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET re… | Patch early | 9.8 critical | 33.1% | 2017-02-22 |
| CVE-2017-3241 EXP | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java… | Patch early | 9.0 critical | 32.8% | 2017-01-27 |
| CVE-2026-4257 EXP | The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in al… | Patch early | 9.8 critical | 32.8% | 2026-03-30 |
| CVE-2022-31885 EXP | Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts. | Patch early | 9.8 critical | 32.8% | 2022-06-28 |
| CVE-2018-15534 EXP | Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a d… | Patch early | 9.8 critical | 32.4% | 2018-08-21 |
| CVE-2011-2013 EXP | Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allo… | Patch early | 9.8 critical | 32.3% | 2011-11-08 |
| CVE-2017-6026 EXP | A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.1… | Patch early | 9.1 critical | 31.8% | 2017-06-30 |
| CVE-2018-13415 EXP | In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.… | Patch early | 9.8 critical | 31.8% | 2018-08-13 |
| CVE-2023-36355 EXP | TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows… | Patch early | 9.9 critical | 31.7% | 2023-06-22 |
| CVE-2019-6714 EXP | An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unaut… | Patch early | 9.8 critical | 31.7% | 2019-03-21 |
| CVE-2012-3807 EXP | Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution. | Patch early | 9.8 critical | 31.6% | 2020-01-09 |
| CVE-2017-3078 EXP | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Succe… | Patch early | 9.8 critical | 30.9% | 2017-06-20 |
| CVE-2018-7300 EXP | Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows… | Patch early | 9.8 critical | 30.6% | 2018-02-22 |
| CVE-2016-2385 EXP | Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows re… | Patch early | 9.8 critical | 30.5% | 2016-04-11 |
| CVE-2016-7182 EXP | The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2… | Patch early | 9.8 critical | 30.3% | 2016-10-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt