CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,648 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,466 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-6548 EXP | Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC… | Patch early | 9.8 critical | 21.3% | 2017-03-09 |
| CVE-2016-9899 EXP | Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Fi… | Patch early | 9.8 critical | 21.1% | 2018-06-11 |
| CVE-2018-5159 EXP | An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-… | Patch early | 9.8 critical | 21% | 2018-06-11 |
| CVE-2021-26599 EXP | ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. | Patch early | 9.8 critical | 21% | 2022-03-28 |
| CVE-2016-4201 EXP | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 20.8% | 2016-07-13 |
| CVE-2018-13417 EXP | In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.… | Patch early | 9.8 critical | 20.7% | 2018-08-13 |
| CVE-2022-40032 EXP | SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execu… | Patch early | 9.8 critical | 20.7% | 2023-02-17 |
| CVE-2018-6481 EXP | A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending… | Patch early | 9.8 critical | 20.7% | 2018-02-27 |
| CVE-2015-6018 EXP | The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary comm… | Patch early | 9.8 critical | 20.6% | 2015-12-31 |
| CVE-2015-4664 EXP | An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands. | Patch early | 9.8 critical | 20.6% | 2018-06-18 |
| CVE-2011-1930 EXP | In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker t… | Patch early | 9.8 critical | 20.5% | 2019-11-14 |
| CVE-2019-14348 EXP | The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-york… | Patch early | 9.8 critical | 20.5% | 2019-08-05 |
| CVE-2022-31125 EXP | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauth… | Patch early | 10.0 critical | 20.3% | 2022-07-06 |
| CVE-2021-27828 EXP | SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavi… | Patch early | 9.1 critical | 20.3% | 2021-06-01 |
| CVE-2018-13416 EXP | In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) att… | Patch early | 9.8 critical | 20.2% | 2018-08-03 |
| CVE-2018-5973 EXP | SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryI… | Patch early | 9.8 critical | 20.1% | 2018-01-25 |
| CVE-2017-4901 EXP | The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory acce… | Patch early | 9.9 critical | 19.9% | 2017-06-08 |
| CVE-2019-9791 EXP | The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMo… | Patch early | 9.8 critical | 19.9% | 2019-04-26 |
| CVE-2007-1399 EXP | Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to e… | Patch early | 9.8 critical | 19.8% | 2007-03-10 |
| CVE-2021-43617 EXP | Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttr… | Patch early | 9.8 critical | 19.8% | 2021-11-14 |
| CVE-2018-5726 EXP | MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request, as demonstrated by the usernam… | Patch early | 9.8 critical | 19.8% | 2018-01-16 |
| CVE-2020-24215 EXP | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP re… | Patch early | 9.8 critical | 19.8% | 2020-10-06 |
| CVE-2019-8049 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 19.7% | 2019-08-20 |
| CVE-2016-6175 EXP | Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header… | Patch early | 9.8 critical | 19.7% | 2017-02-07 |
| CVE-2019-8385 EXP | An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability… | Patch early | 9.8 critical | 19.6% | 2019-06-05 |
| CVE-2016-0952 EXP | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a… | Patch early | 9.8 critical | 19.6% | 2016-02-10 |
| CVE-2016-0953 EXP | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a… | Patch early | 9.8 critical | 19.6% | 2016-02-10 |
| CVE-2016-0951 EXP | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a… | Patch early | 9.8 critical | 19.6% | 2016-02-10 |
| CVE-2021-3018 EXP | ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print… | Patch early | 9.8 critical | 19.5% | 2021-01-05 |
| CVE-2024-24496 EXP | An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tr… | Patch early | 9.8 critical | 19.5% | 2024-02-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt