CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,692 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,469 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-8641 EXP | An out-of-bounds read was addressed with improved input validation. | Patch early | 9.8 critical | 17% | 2019-12-18 |
| CVE-2019-11469 EXP | Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user c… | Patch early | 9.8 critical | 17% | 2019-04-23 |
| CVE-2017-1002008 EXP | Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-membe… | Patch early | 9.8 critical | 16.9% | 2017-09-14 |
| CVE-2014-2595 EXP | Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obt… | Patch early | 9.8 critical | 16.9% | 2020-02-12 |
| CVE-2014-0030 EXP | The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. | Patch early | 9.8 critical | 16.9% | 2017-10-10 |
| CVE-2019-8197 EXP | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | Patch early | 9.8 critical | 16.8% | 2019-10-17 |
| CVE-2019-8042 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 16.8% | 2019-08-20 |
| CVE-2018-15691 EXP | Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute a… | Patch early | 9.8 critical | 16.8% | 2018-08-30 |
| CVE-2018-9843 EXP | The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialize… | Patch early | 9.8 critical | 16.7% | 2018-04-12 |
| CVE-2017-6182 EXP | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command… | Patch early | 9.8 critical | 16.7% | 2017-03-30 |
| CVE-2020-15492 EXP | An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP p… | Patch early | 9.8 critical | 16.6% | 2020-07-23 |
| CVE-2017-6315 EXP | Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx. | Patch early | 9.8 critical | 16.6% | 2017-09-19 |
| CVE-2017-8051 EXP | Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of t… | Patch early | 9.8 critical | 16.5% | 2017-04-21 |
| CVE-2018-13784 EXP | PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php. | Patch early | 9.1 critical | 16.5% | 2018-07-09 |
| CVE-2018-18761 EXP | SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. | Patch early | 9.8 critical | 16.5% | 2018-11-16 |
| CVE-2025-20125 EXP | A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information,… | Patch early | 9.1 critical | 16.4% | 2025-02-05 |
| CVE-2017-11151 EXP | A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files wit… | Patch early | 9.8 critical | 16.3% | 2017-08-08 |
| CVE-2018-14485 EXP | BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. | Patch early | 9.8 critical | 16.3% | 2019-05-07 |
| CVE-2012-6649 EXP | WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload. | Patch early | 9.8 critical | 16.3% | 2020-01-23 |
| CVE-2020-11749 EXP | Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can tri… | Patch early | 9.0 critical | 16.2% | 2020-07-13 |
| CVE-2013-2571 EXP | Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request… | Patch early | 9.8 critical | 16.2% | 2020-01-28 |
| CVE-2021-36711 EXP | WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled. | Patch early | 9.8 critical | 16.1% | 2022-07-16 |
| CVE-2019-8375 EXP | The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script… | Patch early | 9.8 critical | 16.1% | 2019-02-24 |
| CVE-2013-7137 EXP | The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting th… | Patch early | 9.8 critical | 16.1% | 2014-01-26 |
| CVE-2005-2103 EXP | Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly e… | Patch early | 9.8 critical | 16.1% | 2005-08-16 |
| CVE-2015-8396 EXP | Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDC… | Patch early | 10.0 critical | 16% | 2016-01-12 |
| CVE-2019-8045 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 16% | 2019-08-20 |
| CVE-2017-12785 EXP | The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, is prone to a… | Patch early | 9.8 critical | 16% | 2017-08-22 |
| CVE-2020-23935 EXP | Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". | Patch early | 9.8 critical | 15.9% | 2020-08-20 |
| CVE-2020-10230 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parame… | Patch early | 9.8 critical | 15.8% | 2020-03-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt