CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-4879 | An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier v… | Patch early | 9.8 critical | 28.6% | 2018-02-27 |
| CVE-2022-27115 | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | Patch early | 9.8 critical | 28.6% | 2022-04-11 |
| CVE-2023-31222 | Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an… | Patch early | 9.8 critical | 28.5% | 2023-06-29 |
| CVE-2024-24116 | An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm. | Patch early | 9.8 critical | 28.4% | 2024-10-02 |
| CVE-2020-3657 | u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client through webs… | Patch early | 9.8 critical | 28.3% | 2020-11-02 |
| CVE-2024-3429 | A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` fu… | Patch early | 9.8 critical | 28.3% | 2024-06-06 |
| CVE-2017-14706 | DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to /webservices… | Patch early | 9.8 critical | 28.2% | 2017-09-22 |
| CVE-2019-0725 | A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote… | Patch early | 9.8 critical | 28.2% | 2019-05-16 |
| CVE-2018-15957 | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data… | Patch early | 9.8 critical | 28.2% | 2018-09-25 |
| CVE-2019-13375 | A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeA… | Patch early | 9.8 critical | 28.2% | 2019-07-06 |
| CVE-2022-22720 | Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server t… | Patch early | 9.8 critical | 28.2% | 2022-03-14 |
| CVE-2016-0857 | Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors. | Patch early | 9.8 critical | 28.2% | 2016-01-15 |
| CVE-2022-28573 | D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows at… | Patch early | 9.8 critical | 28.2% | 2022-05-02 |
| CVE-2023-52755 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab out of bounds write in smb_inherit_dacl() slab out-of-bounds wri… | Patch early | 9.8 critical | 28.1% | 2024-05-21 |
| CVE-2026-22557 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on th… | Patch early | 10.0 critical | 28.1% | 2026-03-19 |
| CVE-2016-3109 | The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code. | Patch early | 9.8 critical | 28.1% | 2017-04-21 |
| CVE-2019-14529 | OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php. | Patch early | 9.8 critical | 28.1% | 2019-08-02 |
| CVE-2024-10443 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhot… | Patch early | 9.8 critical | 28% | 2024-11-15 |
| CVE-2026-1492 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin… | Patch early | 9.8 critical | 28% | 2026-03-03 |
| CVE-2025-47539 | Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a t… | Patch early | 9.8 critical | 27.9% | 2025-05-23 |
| CVE-2018-15531 | JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java. | Patch early | 9.8 critical | 27.9% | 2018-09-26 |
| CVE-2020-25112 | An issue was discovered in the IPv6 stack in Contiki through 3.0. There are inconsistent checks for IPv6 header extension lengths. This leads to Denia… | Patch early | 9.8 critical | 27.9% | 2020-12-11 |
| CVE-2021-27162 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP. | Patch early | 9.8 critical | 27.8% | 2021-02-10 |
| CVE-2018-3252 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… | Patch early | 9.8 critical | 27.8% | 2018-10-17 |
| CVE-2024-49368 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the… | Patch early | 9.8 critical | 27.7% | 2024-10-21 |
| CVE-2016-4532 | Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to… | Patch early | 9.1 critical | 27.6% | 2016-06-09 |
| CVE-2022-29805 | A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code vi… | Patch early | 9.8 critical | 27.6% | 2022-08-19 |
| CVE-2016-8519 | A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found. | Patch early | 9.8 critical | 27.6% | 2018-02-15 |
| CVE-2019-16124 | In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, a… | Patch early | 9.8 critical | 27.6% | 2019-09-09 |
| CVE-2025-27590 | In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account… | Patch early | 9.0 critical | 27.6% | 2025-03-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt