CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,831 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,488 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-33362 EXP | Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function. | Patch early | 9.8 critical | 9.1% | 2023-05-23 |
| CVE-2016-10043 EXP | An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to OS… | Patch early | 10.0 critical | 9% | 2017-01-31 |
| CVE-2019-9184 EXP | SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the produ… | Patch early | 9.8 critical | 9% | 2019-02-26 |
| CVE-2018-14418 EXP | In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI. | Patch early | 9.8 critical | 9% | 2018-07-20 |
| CVE-2002-1816 EXP | Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via… | Patch early | 9.8 critical | 9% | 2002-12-31 |
| CVE-2022-31056 EXP | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affect… | Patch early | 9.8 critical | 9% | 2022-06-28 |
| CVE-2012-4750 EXP | A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicio… | Patch early | 9.8 critical | 8.9% | 2020-01-13 |
| CVE-2001-1291 EXP | The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or pass… | Patch early | 9.8 critical | 8.9% | 2001-07-12 |
| CVE-2017-4914 EXP | VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote at… | Patch early | 9.8 critical | 8.8% | 2017-06-07 |
| CVE-2017-17111 EXP | Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request. | Patch early | 9.8 critical | 8.8% | 2017-12-11 |
| CVE-2011-3642 EXP | Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, a… | Patch early | 9.6 critical | 8.8% | 2020-02-08 |
| CVE-2017-17055 EXP | Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involv… | Patch early | 9.0 critical | 8.7% | 2017-12-07 |
| CVE-2016-5678 EXP | NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain admin… | Patch early | 9.8 critical | 8.7% | 2016-08-31 |
| CVE-2017-8224 EXP | Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET. | Patch early | 9.8 critical | 8.7% | 2017-04-25 |
| CVE-2018-7318 EXP | SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order p… | Patch early | 9.8 critical | 8.7% | 2018-02-22 |
| CVE-2017-17110 EXP | Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request. | Patch early | 9.8 critical | 8.6% | 2017-12-11 |
| CVE-2018-11736 EXP | An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the… | Patch early | 9.8 critical | 8.6% | 2018-06-05 |
| CVE-2023-27290 EXP | Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require… | Patch early | 9.1 critical | 8.6% | 2023-03-03 |
| CVE-2018-10575 EXP | An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged S… | Patch early | 9.8 critical | 8.5% | 2018-04-30 |
| CVE-2017-2800 EXP | A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate vali… | Patch early | 9.8 critical | 8.5% | 2017-05-24 |
| CVE-2018-9302 EXP | SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TC… | Patch early | 9.1 critical | 8.5% | 2018-05-02 |
| CVE-2013-4743 EXP | Static HTTP Server 1.0 has a Local Overflow | Patch early | 9.8 critical | 8.4% | 2019-12-27 |
| CVE-2015-3313 EXP | SQL injection vulnerability in WordPress Community Events plugin before 1.4. | Patch early | 9.8 critical | 8.3% | 2017-09-07 |
| CVE-2026-24479 EXP | HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj… | Patch early | 9.8 critical | 8.3% | 2026-01-27 |
| CVE-2017-10682 EXP | SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_fa… | Patch early | 9.8 critical | 8.3% | 2017-06-29 |
| CVE-2017-14702 EXP | ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object deserializa… | Patch early | 9.8 critical | 8.3% | 2017-09-30 |
| CVE-2022-24263 EXP | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email p… | Patch early | 9.8 critical | 8.2% | 2022-01-31 |
| CVE-2019-10664 EXP | Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp. | Patch early | 9.8 critical | 8.2% | 2019-03-31 |
| CVE-2001-0766 EXP | Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some character… | Patch early | 9.8 critical | 8.2% | 2001-10-18 |
| CVE-2019-18873 EXP | FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user accoun… | Patch early | 9.0 critical | 8.2% | 2019-11-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt