CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,612 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,461 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-10718 EXP | Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary c… | Patch early | 10.0 critical | 30.2% | 2018-05-03 |
| CVE-2024-22836 EXP | An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to… | Patch early | 9.8 critical | 30% | 2024-02-08 |
| CVE-2017-0561 EXP | A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of th… | Patch early | 9.8 critical | 29.8% | 2017-04-07 |
| CVE-2026-3891 EXP | The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation… | Patch early | 9.8 critical | 29.7% | 2026-03-13 |
| CVE-2017-5173 EXP | An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An im… | Patch early | 9.8 critical | 29.6% | 2017-05-19 |
| CVE-2012-6664 EXP | Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write… | Patch early | 9.1 critical | 29.5% | 2024-06-21 |
| CVE-2020-14011 EXP | Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is… | Patch early | 9.8 critical | 29.5% | 2020-06-15 |
| CVE-2017-11517 EXP | Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote attackers to execute arbitrary c… | Patch early | 9.8 critical | 29.1% | 2017-07-21 |
| CVE-2019-7274 EXP | Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root. | Patch early | 9.8 critical | 29% | 2019-07-01 |
| CVE-2010-0211 EXP | The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows rem… | Patch early | 9.8 critical | 28.5% | 2010-07-28 |
| CVE-2022-31161 EXP | Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via th… | Patch early | 10.0 critical | 28.4% | 2022-07-15 |
| CVE-2018-12327 EXP | Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges vi… | Patch early | 9.8 critical | 28% | 2018-06-20 |
| CVE-2019-8982 EXP | com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to discl… | Patch early | 9.6 critical | 28% | 2019-02-21 |
| CVE-2018-9032 EXP | An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version… | Patch early | 9.8 critical | 27.7% | 2018-03-27 |
| CVE-2019-25024 EXP | OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service paramete… | Patch early | 9.8 critical | 27.6% | 2021-02-19 |
| CVE-2017-1002000 EXP | Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/im… | Patch early | 9.8 critical | 27.4% | 2017-09-14 |
| CVE-2017-16562 EXP | The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and… | Patch early | 9.8 critical | 27.4% | 2017-11-10 |
| CVE-2018-7750 EXP | transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.… | Patch early | 9.8 critical | 27.1% | 2018-03-13 |
| CVE-2016-4203 EXP | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 26.9% | 2016-07-13 |
| CVE-2020-35314 EXP | A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to uploa… | Patch early | 9.8 critical | 26.9% | 2021-04-20 |
| CVE-2007-5775 EXP | Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029… | Patch early | 9.8 critical | 26.9% | 2007-11-01 |
| CVE-2017-6359 EXP | QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors. | Patch early | 9.8 critical | 26.9% | 2017-03-23 |
| CVE-2020-11819 EXP | In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution. | Patch early | 9.8 critical | 26.8% | 2020-04-16 |
| CVE-2013-2570 EXP | A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the bi… | Patch early | 9.8 critical | 26.6% | 2020-01-29 |
| CVE-2013-6225 EXP | LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability | Patch early | 9.8 critical | 26.6% | 2020-01-13 |
| CVE-2018-8733 EXP | Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to ma… | Patch early | 9.8 critical | 26.6% | 2018-04-18 |
| CVE-2022-24627 EXP | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the… | Patch early | 9.8 critical | 26.4% | 2023-05-29 |
| CVE-2019-19576 EXP | class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar… | Patch early | 9.8 critical | 26.4% | 2019-12-04 |
| CVE-2020-20277 EXP | There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to impro… | Patch early | 9.8 critical | 26.2% | 2020-12-18 |
| CVE-2018-17057 EXP | An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper. | Patch early | 9.8 critical | 26.2% | 2018-09-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt