CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,612 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,465 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-6024 EXP | ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execu… | Patch early | 9.8 critical | 26.1% | 2017-02-09 |
| CVE-2024-24724 EXP | Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because in… | Patch early | 9.8 critical | 26.1% | 2024-04-03 |
| CVE-2019-1913 EXP | Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote atta… | Patch early | 9.8 critical | 25.9% | 2019-08-07 |
| CVE-2018-15152 EXP | Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal… | Patch early | 9.1 critical | 25.9% | 2018-08-15 |
| CVE-2019-16072 EXP | An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitr… | Patch early | 9.8 critical | 25.9% | 2020-03-20 |
| CVE-2016-10036 EXP | Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servl… | Patch early | 9.8 critical | 25.6% | 2018-05-01 |
| CVE-2019-15106 EXP | An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on th… | Patch early | 9.8 critical | 25.5% | 2019-08-16 |
| CVE-2016-4138 EXP | Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… | Patch early | 9.8 critical | 25.4% | 2016-06-16 |
| CVE-2016-2851 EXP | Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and app… | Patch early | 9.8 critical | 25.4% | 2016-04-07 |
| CVE-2017-5586 EXP | OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, re… | Patch early | 9.8 critical | 25.3% | 2017-02-22 |
| CVE-2021-3278 EXP | Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an… | Patch early | 9.8 critical | 25.3% | 2021-01-26 |
| CVE-2017-12786 EXP | Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwit… | Patch early | 9.8 critical | 25.3% | 2017-08-22 |
| CVE-2020-35948 EXP | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify ar… | Patch early | 9.9 critical | 24.9% | 2021-01-01 |
| CVE-2018-19864 EXP | NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer ove… | Patch early | 9.8 critical | 24.8% | 2018-12-05 |
| CVE-2019-16119 EXP | SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album… | Patch early | 9.8 critical | 24.8% | 2019-09-08 |
| CVE-2016-5108 EXP | Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a… | Patch early | 9.8 critical | 24.7% | 2016-06-08 |
| CVE-2017-3076 EXP | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC module. Successful exploitati… | Patch early | 9.8 critical | 24.7% | 2017-06-20 |
| CVE-2017-3061 EXP | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. Successful exploitation coul… | Patch early | 9.8 critical | 24.7% | 2017-04-12 |
| CVE-2019-5893 EXP | Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter. | Patch early | 9.8 critical | 24.7% | 2019-01-10 |
| CVE-2014-4650 EXP | The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remot… | Patch early | 9.8 critical | 24.7% | 2020-02-20 |
| CVE-2013-7052 EXP | D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script | Patch early | 9.8 critical | 24.7% | 2020-02-04 |
| CVE-2016-3645 EXP | Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:S… | Patch early | 9.8 critical | 24.6% | 2016-06-30 |
| CVE-2017-12787 EXP | A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviS… | Patch early | 9.8 critical | 24.6% | 2017-08-22 |
| CVE-2019-13360 EXP | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge o… | Patch early | 9.8 critical | 24.5% | 2019-07-16 |
| CVE-2018-11652 EXP | CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP respons… | Patch early | 9.8 critical | 24.4% | 2018-06-01 |
| CVE-2013-1592 EXP | A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Serve… | Patch early | 9.8 critical | 24.4% | 2020-01-23 |
| CVE-2019-13577 EXP | SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature liste… | Patch early | 9.8 critical | 24.4% | 2019-07-17 |
| CVE-2018-12584 EXP | The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a denia… | Patch early | 9.8 critical | 24.3% | 2018-07-16 |
| CVE-2024-25830 EXP | F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker… | Patch early | 9.8 critical | 24% | 2024-02-29 |
| CVE-2017-8798 EXP | Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspec… | Patch early | 9.8 critical | 24% | 2017-05-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt