CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,759 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,483 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-35775 EXP | CITSmart before 9.1.2.23 allows LDAP Injection. | Patch early | 9.8 critical | 13.3% | 2021-02-15 |
| CVE-2019-8613 EXP | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may… | Patch early | 9.8 critical | 13.3% | 2019-12-18 |
| CVE-2019-9792 EXP | The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value c… | Patch early | 9.8 critical | 13.2% | 2019-04-26 |
| CVE-2013-4982 EXP | AVTECH AVN801 DVR has a security bypass via the administration login captcha | Patch early | 9.8 critical | 13.1% | 2019-12-27 |
| CVE-2013-2748 EXP | Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system. | Patch early | 9.8 critical | 13.1% | 2020-01-28 |
| CVE-2019-4013 EXP | IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code… | Patch early | 9.0 critical | 13% | 2019-04-10 |
| CVE-2009-4488 EXP | Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or… | Patch early | 9.8 critical | 13% | 2010-01-13 |
| CVE-2017-7462 EXP | Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory. | Patch early | 9.8 critical | 13% | 2017-04-11 |
| CVE-2006-6863 EXP | PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PH… | Patch early | 9.8 critical | 13% | 2006-12-31 |
| CVE-2019-15039 EXP | An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1. | Patch early | 9.8 critical | 12.9% | 2019-10-01 |
| CVE-2024-27746 EXP | SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email ad… | Patch early | 9.8 critical | 12.9% | 2024-03-01 |
| CVE-2006-7079 EXP | Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables a… | Patch early | 9.8 critical | 12.9% | 2007-03-02 |
| CVE-2022-2840 EXP | The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via vario… | Patch early | 9.8 critical | 12.9% | 2022-09-19 |
| CVE-2018-9022 EXP | An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands… | Patch early | 9.8 critical | 12.8% | 2018-06-18 |
| CVE-2018-8898 EXP | A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer=… | Patch early | 9.8 critical | 12.8% | 2018-05-23 |
| CVE-2018-6911 EXP | The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argumen… | Patch early | 9.8 critical | 12.8% | 2018-02-13 |
| CVE-2020-6627 EXP | The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_lau… | Patch early | 9.8 critical | 12.8% | 2022-12-06 |
| CVE-2018-10285 EXP | The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attack… | Patch early | 9.8 critical | 12.8% | 2018-04-22 |
| CVE-2017-14097 EXP | An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to decrypt… | Patch early | 9.8 critical | 12.7% | 2018-01-19 |
| CVE-2014-9611 EXP | Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/in… | Patch early | 9.8 critical | 12.7% | 2017-09-19 |
| CVE-2017-1002002 EXP | Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/ | Patch early | 9.8 critical | 12.6% | 2017-09-14 |
| CVE-2017-14459 EXP | An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a… | Patch early | 10.0 critical | 12.6% | 2018-04-11 |
| CVE-2018-11509 EXP | ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from t… | Patch early | 9.8 critical | 12.6% | 2018-08-16 |
| CVE-2018-19862 EXP | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is… | Patch early | 9.8 critical | 12.6% | 2019-01-03 |
| CVE-2018-19861 EXP | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is… | Patch early | 9.8 critical | 12.6% | 2019-01-03 |
| CVE-2017-17976 EXP | In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. | Patch early | 9.8 critical | 12.5% | 2018-01-26 |
| CVE-2018-10824 EXP | An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-… | Patch early | 9.8 critical | 12.5% | 2018-10-17 |
| CVE-2016-7567 EXP | Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a craf… | Patch early | 9.8 critical | 12.5% | 2017-01-23 |
| CVE-2019-11448 EXP | An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the s… | Patch early | 9.8 critical | 12.4% | 2019-04-22 |
| CVE-2022-24082 EXP | If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not… | Patch early | 9.8 critical | 12.3% | 2022-07-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt