CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,058 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,702 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-12848 | Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds write v… | Patch early | 9.8 critical | 34.7% | 2018-09-25 |
| CVE-2021-31324 | The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution. | Patch early | 9.8 critical | 34.6% | 2021-05-18 |
| CVE-2017-14803 | In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugi… | Patch early | 9.8 critical | 34.6% | 2018-01-20 |
| CVE-2022-24497 | Windows Network File System Remote Code Execution Vulnerability | Patch early | 9.8 critical | 34.6% | 2022-04-15 |
| CVE-2024-5315 | Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a… | Patch early | 9.1 critical | 34.5% | 2024-05-24 |
| CVE-2024-31982 | XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database… | Patch early | 10.0 critical | 34.5% | 2024-04-10 |
| CVE-2022-28927 | A remote code execution (RCE) vulnerability in Subconverter v0.7.2 allows attackers to execute arbitrary code via crafted config and url parameters. | Patch early | 9.8 critical | 34.4% | 2022-05-19 |
| CVE-2022-0349 | The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Una… | Patch early | 9.8 critical | 34.4% | 2022-03-07 |
| CVE-2024-4320 | A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within… | Patch early | 9.8 critical | 34.4% | 2024-06-06 |
| CVE-2023-1650 | The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could a… | Patch early | 9.8 critical | 34.4% | 2023-05-08 |
| CVE-2018-3991 | An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, version 6.40.2402.500. A special… | Patch early | 10.0 critical | 34.3% | 2019-02-05 |
| CVE-2024-1651 | Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deser… | Patch early | 10.0 critical | 34.2% | 2024-02-20 |
| CVE-2024-42008 | A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to s… | Patch early | 9.3 critical | 34.2% | 2024-08-05 |
| CVE-2020-4450 | IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafte… | Patch early | 9.8 critical | 34.2% | 2020-06-05 |
| CVE-2024-39280 | An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted H… | Patch early | 9.1 critical | 34.2% | 2025-01-14 |
| CVE-2025-28137 | The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function throug… | Patch early | 9.8 critical | 34.1% | 2025-04-15 |
| CVE-2022-32548 | An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overf… | Patch early | 10.0 critical | 34% | 2022-08-29 |
| CVE-2020-1947 | In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load d… | Patch early | 9.8 critical | 33.9% | 2020-03-11 |
| CVE-2023-27584 | Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as… | Patch early | 9.8 critical | 33.9% | 2024-09-19 |
| CVE-2019-18937 | eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attacke… | Patch early | 9.8 critical | 33.8% | 2019-11-14 |
| CVE-2019-18938 | eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers… | Patch early | 9.8 critical | 33.8% | 2019-11-14 |
| CVE-2021-26412 | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch early | 9.1 critical | 33.8% | 2021-03-03 |
| CVE-2023-48084 | Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool. | Patch early | 9.8 critical | 33.7% | 2023-12-14 |
| CVE-2016-1000031 | Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution | Patch early | 9.8 critical | 33.7% | 2016-10-25 |
| CVE-2025-10573 | Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the co… | Patch early | 9.6 critical | 33.5% | 2025-12-09 |
| CVE-2020-13921 | **Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases. | Patch early | 9.8 critical | 33.5% | 2020-08-05 |
| CVE-2022-24491 | Windows Network File System Remote Code Execution Vulnerability | Patch early | 9.8 critical | 33.5% | 2022-04-15 |
| CVE-2022-38545 | Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted PO… | Patch early | 9.6 critical | 33.5% | 2022-09-19 |
| CVE-2021-32607 | An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/PrivateMessages/View.cshtml does not call HtmlUtils.SanitizeHtml on a p… | Patch early | 9.8 critical | 33.4% | 2021-05-12 |
| CVE-2021-32608 | An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/Boards/Partials/_ForumPost.cshtml does not call HtmlUtils.SanitizeHtml… | Patch early | 9.8 critical | 33.4% | 2021-05-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt