CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,648 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,465 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-8322 EXP | Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code… | Patch early | 9.8 critical | 23.9% | 2020-01-31 |
| CVE-2024-27747 EXP | File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Imag… | Patch early | 9.8 critical | 23.6% | 2024-03-01 |
| CVE-2018-6396 EXP | SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or… | Patch early | 9.8 critical | 23.6% | 2018-02-17 |
| CVE-2018-5997 EXP | An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it… | Patch early | 9.8 critical | 23.5% | 2018-01-25 |
| CVE-2023-37629 EXP | Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig… | Patch early | 9.8 critical | 23.3% | 2023-07-12 |
| CVE-2016-9682 EXP | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrati… | Patch early | 9.8 critical | 23.3% | 2017-02-22 |
| CVE-2005-3120 EXP | Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article… | Patch early | 9.8 critical | 23.3% | 2005-10-17 |
| CVE-2013-1360 EXP | An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Ma… | Patch early | 9.8 critical | 23.2% | 2020-02-11 |
| CVE-2019-7265 EXP | Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH). | Patch early | 9.8 critical | 23.1% | 2019-07-02 |
| CVE-2021-44567 EXP | An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php. | Patch early | 9.8 critical | 23.1% | 2022-02-24 |
| CVE-2017-15367 EXP | Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depe… | Patch early | 9.8 critical | 23.1% | 2018-03-07 |
| CVE-2023-48292 EXP | The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior to version 4.5.1, a cross site… | Patch early | 9.6 critical | 22.9% | 2023-11-20 |
| CVE-2021-44596 EXP | Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can commu… | Patch early | 9.8 critical | 22.9% | 2022-04-29 |
| CVE-2019-8196 EXP | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | Patch early | 9.8 critical | 22.9% | 2019-10-17 |
| CVE-2019-8195 EXP | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | Patch early | 9.8 critical | 22.9% | 2019-10-17 |
| CVE-2015-8617 EXP | Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute… | Patch early | 9.8 critical | 22.8% | 2016-01-19 |
| CVE-2018-6871 EXP | LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.M… | Patch early | 9.8 critical | 22.8% | 2018-02-09 |
| CVE-2016-9565 EXP | MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing… | Patch early | 9.8 critical | 22.7% | 2016-12-15 |
| CVE-2019-17124 EXP | Kramer VIAware 2.5.0719.1034 has Incorrect Access Control. | Patch early | 9.8 critical | 22.5% | 2019-10-09 |
| CVE-2018-19126 EXP | PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload. | Patch early | 9.8 critical | 22.5% | 2018-11-09 |
| CVE-2018-12596 EXP | Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via… | Patch early | 9.8 critical | 22.4% | 2018-10-10 |
| CVE-2016-3987 EXP | The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefa… | Patch early | 9.8 critical | 22.3% | 2016-04-12 |
| CVE-2017-3077 EXP | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful exploitatio… | Patch early | 9.8 critical | 22.3% | 2017-06-20 |
| CVE-2003-0899 EXP | Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '… | Patch early | 9.8 critical | 22.2% | 2003-11-03 |
| CVE-2019-8016 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 22% | 2019-08-20 |
| CVE-2017-3623 EXP | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are affected see n… | Patch early | 10.0 critical | 22% | 2017-04-24 |
| CVE-2018-8057 EXP | A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/ad… | Patch early | 9.8 critical | 21.8% | 2018-03-11 |
| CVE-2017-6542 EXP | The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent proto… | Patch early | 9.8 critical | 21.8% | 2017-03-27 |
| CVE-2018-20525 EXP | Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php. | Patch early | 9.1 critical | 21.6% | 2019-03-21 |
| CVE-2017-3195 EXP | Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnera… | Patch early | 9.8 critical | 21.4% | 2017-12-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt