CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,733 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,476 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-2641 EXP | In Moodle 2.x and 3.x, SQL injection can occur via user preferences. | Patch early | 9.8 critical | 14.5% | 2017-03-26 |
| CVE-2014-4170 EXP | A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script,… | Patch early | 9.8 critical | 14.5% | 2020-02-13 |
| CVE-2018-9248 EXP | FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header. | Patch early | 9.8 critical | 14.5% | 2018-04-04 |
| CVE-2019-8044 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 14.5% | 2019-08-20 |
| CVE-2019-3025 EXP | Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported version that is affected is 5.7. Di… | Patch early | 9.0 critical | 14.5% | 2019-10-16 |
| CVE-2019-13597 EXP | _s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one can… | Patch early | 9.8 critical | 14.3% | 2019-07-14 |
| CVE-2018-11742 EXP | NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI. | Patch early | 9.8 critical | 14.3% | 2018-12-26 |
| CVE-2017-6880 EXP | Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other… | Patch early | 9.8 critical | 14.3% | 2017-03-17 |
| CVE-2015-7246 EXP | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account,… | Patch early | 9.8 critical | 14.3% | 2017-04-24 |
| CVE-2023-33584 EXP | Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries exe… | Patch early | 9.8 critical | 14.2% | 2023-06-21 |
| CVE-2015-9098 EXP | In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in the ability… | Patch early | 9.8 critical | 14.1% | 2017-06-22 |
| CVE-2022-22832 EXP | An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request. | Patch early | 9.8 critical | 14.1% | 2022-02-06 |
| CVE-2018-7702 EXP | SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary re… | Patch early | 9.1 critical | 14% | 2018-03-15 |
| CVE-2013-4659 EXP | Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on route… | Patch early | 9.8 critical | 13.9% | 2017-03-14 |
| CVE-2015-7874 EXP | Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname. | Patch early | 9.8 critical | 13.9% | 2020-01-15 |
| CVE-2018-12463 EXP | An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to… | Patch early | 9.8 critical | 13.8% | 2018-07-12 |
| CVE-2017-18001 EXP | Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys dat… | Patch early | 9.8 critical | 13.8% | 2017-12-31 |
| CVE-2019-8660 EXP | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3.… | Patch early | 9.8 critical | 13.8% | 2019-12-18 |
| CVE-2021-33216 EXP | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer… | Patch early | 9.8 critical | 13.8% | 2021-07-07 |
| CVE-2009-4491 EXP | thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or… | Patch early | 9.8 critical | 13.7% | 2010-01-13 |
| CVE-2019-6971 EXP | An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management web… | Patch early | 9.8 critical | 13.7% | 2019-06-19 |
| CVE-2002-1484 EXP | DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other sy… | Patch early | 9.8 critical | 13.7% | 2003-04-22 |
| CVE-2015-0565 EXP | NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible. | Patch early | 10.0 critical | 13.6% | 2020-02-25 |
| CVE-2015-7241 EXP | XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01. | Patch early | 9.8 critical | 13.5% | 2017-09-06 |
| CVE-2017-16934 EXP | The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content… | Patch early | 9.8 critical | 13.5% | 2017-11-24 |
| CVE-2019-8647 EXP | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. A remote attacker may b… | Patch early | 9.8 critical | 13.5% | 2019-12-18 |
| CVE-2016-9269 EXP | Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_B… | Patch early | 9.9 critical | 13.4% | 2017-02-21 |
| CVE-2015-8556 EXP | Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1. | Patch early | 10.0 critical | 13.4% | 2017-03-24 |
| CVE-2016-9796 EXP | Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024. An at… | Patch early | 9.8 critical | 13.4% | 2016-12-03 |
| CVE-2019-8017 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 13.3% | 2019-08-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt