CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,959 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,699 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-6079 | The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific… | Patch early | 9.8 critical | 46.8% | 2017-05-16 |
| CVE-2017-16943 | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of… | Patch early | 9.8 critical | 46.7% | 2017-11-25 |
| CVE-2024-20017 | In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional… | Patch early | 9.8 critical | 46.6% | 2024-03-04 |
| CVE-2020-8771 | The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logg… | Patch early | 9.8 critical | 46.5% | 2020-02-06 |
| CVE-2022-47939 | An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_D… | Patch early | 9.8 critical | 46.4% | 2022-12-23 |
| CVE-2017-6517 | Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted sys… | Patch early | 9.8 critical | 46.3% | 2017-03-23 |
| CVE-2023-31465 | An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find… | Patch early | 9.8 critical | 46.3% | 2023-07-26 |
| CVE-2024-44849 | Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php. | Patch early | 9.8 critical | 46.3% | 2024-09-09 |
| CVE-2023-2982 | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions u… | Patch early | 9.8 critical | 46.2% | 2023-06-29 |
| CVE-2021-24442 | The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter… | Patch early | 9.8 critical | 46% | 2021-07-12 |
| CVE-2024-24401 | SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.ph… | Patch early | 9.8 critical | 45.9% | 2024-02-26 |
| CVE-2023-51573 | Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This vulnerability allows remote a… | Patch early | 9.8 critical | 45.7% | 2024-04-01 |
| CVE-2024-51568 | CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filema… | Patch early | 10.0 critical | 45.7% | 2024-10-29 |
| CVE-2020-8165 | A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided… | Patch early | 9.8 critical | 45.7% | 2020-06-19 |
| CVE-2022-2274 | The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes… | Patch early | 9.8 critical | 45.7% | 2022-07-01 |
| CVE-2021-27886 | rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter… | Patch early | 9.8 critical | 45.6% | 2021-03-02 |
| CVE-2023-32562 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve… | Patch early | 9.8 critical | 45.6% | 2023-08-10 |
| CVE-2019-8457 | SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables. | Patch early | 9.8 critical | 45.4% | 2019-05-30 |
| CVE-2019-18952 | SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execut… | Patch early | 9.8 critical | 45.4% | 2019-11-13 |
| CVE-2019-5127 | A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthent… | Patch early | 9.8 critical | 45.3% | 2019-10-25 |
| CVE-2025-34027 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at att… | Patch early | 9.0 critical | 45.2% | 2025-05-21 |
| CVE-2025-43562 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Com… | Patch early | 9.1 critical | 45.1% | 2025-05-13 |
| CVE-2020-26879 | Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the servic… | Patch early | 9.8 critical | 45.1% | 2020-10-26 |
| CVE-2022-45938 | An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field u… | Patch early | 9.0 critical | 45.1% | 2023-06-02 |
| CVE-2024-8181 | An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as… | Patch early | 9.8 critical | 45.1% | 2024-08-27 |
| CVE-2020-7373 | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.… | Patch early | 9.8 critical | 45% | 2020-10-30 |
| CVE-2008-4835 | SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote at… | Patch early | 9.8 critical | 44.9% | 2009-01-14 |
| CVE-2019-16891 | Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload. | Patch early | 9.8 critical | 44.7% | 2019-10-04 |
| CVE-2023-34051 | VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operati… | Patch early | 9.8 critical | 44.7% | 2023-10-20 |
| CVE-2022-33980 | Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for in… | Patch early | 9.8 critical | 44.6% | 2022-07-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt