CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,045 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,701 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-5129 | A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthent… | Patch early | 9.8 critical | 38.5% | 2019-10-25 |
| CVE-2023-5399 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files… | Patch early | 9.8 critical | 38.5% | 2023-10-04 |
| CVE-2017-11383 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation… | Patch early | 9.8 critical | 38.5% | 2017-08-02 |
| CVE-2017-11384 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation… | Patch early | 9.8 critical | 38.5% | 2017-08-02 |
| CVE-2017-11385 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation… | Patch early | 9.8 critical | 38.5% | 2017-08-02 |
| CVE-2024-29849 | Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. | Patch early | 9.8 critical | 38.4% | 2024-05-22 |
| CVE-2023-51572 | Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e… | Patch early | 9.8 critical | 38.4% | 2024-04-01 |
| CVE-2022-2754 | The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL s… | Patch early | 9.8 critical | 38.3% | 2022-09-19 |
| CVE-2015-5254 | Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitra… | Patch early | 9.8 critical | 38.2% | 2016-01-08 |
| CVE-2023-50917 | MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Major… | Patch early | 9.8 critical | 38% | 2023-12-15 |
| CVE-2016-0003 | Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Microsoft Edge Memory Corruption Vulnerability." | Patch early | 9.6 critical | 38% | 2016-01-13 |
| CVE-2017-14469 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… | Patch early | 10.0 critical | 38% | 2018-04-05 |
| CVE-2017-14470 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… | Patch early | 10.0 critical | 38% | 2018-04-05 |
| CVE-2017-14471 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… | Patch early | 10.0 critical | 38% | 2018-04-05 |
| CVE-2017-14472 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… | Patch early | 10.0 critical | 38% | 2018-04-05 |
| CVE-2017-14473 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… | Patch early | 10.0 critical | 38% | 2018-04-05 |
| CVE-2017-14464 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… | Patch early | 9.8 critical | 38% | 2018-04-05 |
| CVE-2017-14466 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… | Patch early | 9.8 critical | 38% | 2018-04-05 |
| CVE-2017-14468 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… | Patch early | 9.8 critical | 38% | 2018-04-05 |
| CVE-2022-28127 | A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request c… | Patch early | 9.1 critical | 37.9% | 2022-06-30 |
| CVE-2017-12556 | A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. | Patch early | 9.8 critical | 37.9% | 2018-02-15 |
| CVE-2017-12558 | A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. | Patch early | 9.8 critical | 37.9% | 2018-02-15 |
| CVE-2021-43711 | The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The pa… | Patch early | 9.8 critical | 37.8% | 2022-01-04 |
| CVE-2017-7525 | A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user t… | Patch early | 9.8 critical | 37.7% | 2018-02-06 |
| CVE-2023-39367 | An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted… | Patch early | 9.1 critical | 37.7% | 2024-04-17 |
| CVE-2024-7094 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution i… | Patch early | 9.8 critical | 37.6% | 2024-08-13 |
| CVE-2022-26833 | An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafte… | Patch early | 9.4 critical | 37.6% | 2022-05-25 |
| CVE-2024-2083 | A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit thi… | Patch early | 9.9 critical | 37.5% | 2024-04-16 |
| CVE-2021-32955 | Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code. | Patch early | 9.8 critical | 37.3% | 2021-08-30 |
| CVE-2017-14467 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… | Patch early | 9.8 critical | 37.3% | 2018-04-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt