CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,516 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
36,565 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-16399 EXP | Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory witho… | Patch early | 9.8 critical | 7.1% | 2019-09-18 |
| CVE-2016-9684 EXP | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative i… | Patch early | 9.8 critical | 7.1% | 2017-02-22 |
| CVE-2014-5381 EXP | Grand MA 300 allows a brute-force attack on the PIN. | Patch early | 9.8 critical | 7.1% | 2020-01-13 |
| CVE-2013-7055 EXP | D-Link DIR-100 4.03B07 has PPTP and poe information disclosure | Patch early | 9.8 critical | 7% | 2020-02-04 |
| CVE-2023-37759 EXP | Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an… | Patch early | 9.8 critical | 7% | 2023-09-08 |
| CVE-2017-17097 EXP | gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated reques… | Patch early | 9.8 critical | 6.9% | 2018-01-02 |
| CVE-2025-3605 EXP | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and… | Patch early | 9.8 critical | 6.9% | 2025-05-09 |
| CVE-2015-4683 EXP | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by levera… | Patch early | 9.8 critical | 6.9% | 2017-09-19 |
| CVE-2013-4103 EXP | Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input | Patch early | 9.8 critical | 6.9% | 2019-11-04 |
| CVE-2016-8580 EXP | PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PH… | Patch early | 9.8 critical | 6.9% | 2016-10-28 |
| CVE-2017-2527 EXP | An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimation" component. It allows remot… | Patch early | 9.8 critical | 6.8% | 2017-05-22 |
| CVE-2018-10653 EXP | There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | Patch early | 9.8 critical | 6.8% | 2018-05-23 |
| CVE-2026-34156 EXP | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's W… | Patch early | 9.9 critical | 6.8% | 2026-03-31 |
| CVE-2017-2524 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | Patch early | 9.8 critical | 6.7% | 2017-05-22 |
| CVE-2017-7237 EXP | The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directo… | Patch early | 9.8 critical | 6.7% | 2017-04-06 |
| CVE-2010-1866 EXP | The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of se… | Patch early | 9.8 critical | 6.7% | 2010-05-07 |
| CVE-2022-23366 EXP | HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php. | Patch early | 9.8 critical | 6.7% | 2022-01-21 |
| CVE-2017-17098 EXP | The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary P… | Patch early | 9.8 critical | 6.6% | 2018-01-02 |
| CVE-2019-0285 EXP | The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including creden… | Patch early | 9.8 critical | 6.6% | 2019-04-10 |
| CVE-2017-2522 EXP | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | Patch early | 9.8 critical | 6.6% | 2017-05-22 |
| CVE-2015-8282 EXP | SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account. | Patch early | 9.8 critical | 6.6% | 2017-04-13 |
| CVE-2017-7175 EXP | NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom outpu… | Patch early | 9.9 critical | 6.5% | 2017-07-10 |
| CVE-2018-4367 EXP | A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1. | Patch early | 9.8 critical | 6.5% | 2019-04-03 |
| CVE-2023-0744 EXP | Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4. | Patch early | 9.8 critical | 6.4% | 2023-02-08 |
| CVE-2026-25895 EXP | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote att… | Patch early | 9.8 critical | 6.3% | 2026-02-09 |
| CVE-2021-45814 EXP | Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account… | Patch early | 9.8 critical | 6.3% | 2021-12-28 |
| CVE-2020-14944 EXP | Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeov… | Patch early | 9.8 critical | 6.3% | 2020-06-22 |
| CVE-2013-4864 EXP | MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/prox… | Patch early | 9.8 critical | 6.3% | 2020-01-28 |
| CVE-2017-5344 EXP | An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet per… | Patch early | 9.8 critical | 6.3% | 2017-02-17 |
| CVE-2019-8352 EXP | By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed… | Patch early | 9.8 critical | 6.3% | 2019-05-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt