CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-8589 | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… | Patch early | 9.8 critical | 26.2% | 2017-07-11 |
| CVE-2021-24074 | Windows TCP/IP Remote Code Execution Vulnerability | Patch early | 9.8 critical | 26.2% | 2021-02-25 |
| CVE-2019-6703 | Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated… | Patch early | 9.8 critical | 26.1% | 2019-01-27 |
| CVE-2023-31719 | FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin. | Patch early | 9.8 critical | 26% | 2023-09-22 |
| CVE-2024-34359 | llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency… | Patch early | 9.6 critical | 26% | 2024-05-14 |
| CVE-2024-23624 | A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability… | Patch early | 9.6 critical | 26% | 2024-01-26 |
| CVE-2022-35555 | A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for… | Patch early | 9.8 critical | 26% | 2022-08-12 |
| CVE-2023-33831 | A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a craf… | Patch early | 9.8 critical | 26% | 2023-09-18 |
| CVE-2022-1020 | The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_… | Patch early | 9.8 critical | 25.9% | 2022-04-18 |
| CVE-2025-27364 | In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilat… | Patch early | 10.0 critical | 25.9% | 2025-02-24 |
| CVE-2022-37159 | Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload. | Patch early | 9.8 critical | 25.9% | 2022-08-25 |
| CVE-2022-47071 | In NVS365 V01, the background network test function can trigger command execution. | Patch early | 9.8 critical | 25.9% | 2023-02-06 |
| CVE-2023-30013 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerab… | Patch early | 9.8 critical | 25.9% | 2023-05-05 |
| CVE-2018-15958 | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data… | Patch early | 9.8 critical | 25.9% | 2018-09-25 |
| CVE-2018-15959 | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data… | Patch early | 9.8 critical | 25.9% | 2018-09-25 |
| CVE-2018-15965 | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data… | Patch early | 9.8 critical | 25.9% | 2018-09-25 |
| CVE-2022-30887 | Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.p… | Patch early | 9.8 critical | 25.8% | 2022-05-20 |
| CVE-2023-33404 | An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows… | Patch early | 9.8 critical | 25.8% | 2023-06-26 |
| CVE-2021-21669 | Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | Patch early | 9.8 critical | 25.7% | 2021-06-18 |
| CVE-2019-7091 | ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Succ… | Patch early | 9.8 critical | 25.7% | 2019-05-24 |
| CVE-2022-37057 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main. | Patch early | 9.8 critical | 25.6% | 2022-08-28 |
| CVE-2024-9487 | An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to b… | Patch early | 9.1 critical | 25.6% | 2024-10-10 |
| CVE-2022-26213 | Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz para… | Patch early | 9.8 critical | 25.6% | 2022-03-15 |
| CVE-2022-39214 | Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able t… | Patch early | 9.6 critical | 25.6% | 2023-03-14 |
| CVE-2025-6934 | The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vuln… | Patch early | 9.8 critical | 25.6% | 2025-07-01 |
| CVE-2025-22954 | GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid p… | Patch early | 10.0 critical | 25.6% | 2025-03-12 |
| CVE-2024-5182 | A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion… | Patch early | 9.1 critical | 25.5% | 2024-06-20 |
| CVE-2022-32532 | Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatche… | Patch early | 9.8 critical | 25.5% | 2022-06-29 |
| CVE-2024-6386 | The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Inject… | Patch early | 9.9 critical | 25.5% | 2024-08-21 |
| CVE-2025-60021 | Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to i… | Patch early | 9.8 critical | 25.5% | 2026-01-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt