CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,071 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-0786 | Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remote… | Patch early | 9.8 critical | 23.6% | 2017-08-09 |
| CVE-2022-45551 | An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Netw… | Patch early | 9.8 critical | 23.6% | 2023-03-03 |
| CVE-2021-27145 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP. | Patch early | 9.8 critical | 23.6% | 2021-02-10 |
| CVE-2021-27148 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an… | Patch early | 9.8 critical | 23.6% | 2021-02-10 |
| CVE-2021-27149 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credent… | Patch early | 9.8 critical | 23.6% | 2021-02-10 |
| CVE-2021-27158 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP. | Patch early | 9.8 critical | 23.6% | 2021-02-10 |
| CVE-2021-27164 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / aisadmin credentials for an ISP. | Patch early | 9.8 critical | 23.6% | 2021-02-10 |
| CVE-2025-30281 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code… | Patch early | 9.1 critical | 23.6% | 2025-04-08 |
| CVE-2016-5649 | A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1… | Patch early | 9.8 critical | 23.6% | 2018-07-24 |
| CVE-2016-7117 | Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitr… | Patch early | 9.8 critical | 23.6% | 2016-10-10 |
| CVE-2023-46454 | In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package inf… | Patch early | 9.8 critical | 23.5% | 2023-12-12 |
| CVE-2022-34974 | D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function. | Patch early | 9.8 critical | 23.5% | 2022-08-03 |
| CVE-2024-11773 | SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrar… | Patch early | 9.1 critical | 23.5% | 2024-12-10 |
| CVE-2021-21132 | Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via… | Patch early | 9.6 critical | 23.4% | 2021-02-09 |
| CVE-2020-1957 | Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass. | Patch early | 9.8 critical | 23.3% | 2020-03-25 |
| CVE-2020-24719 | Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (a… | Patch early | 9.8 critical | 23.3% | 2020-11-12 |
| CVE-2020-5777 | MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database c… | Patch early | 9.8 critical | 23.3% | 2020-09-01 |
| CVE-2021-3177 | Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applica… | Patch early | 9.8 critical | 23.3% | 2021-01-19 |
| CVE-2017-7376 | Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects. | Patch early | 9.8 critical | 23.3% | 2018-02-19 |
| CVE-2021-42669 | A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar throug… | Patch early | 9.8 critical | 23.3% | 2021-11-05 |
| CVE-2025-0851 | A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary… | Patch early | 9.8 critical | 23.3% | 2025-01-29 |
| CVE-2019-12260 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer… | Patch early | 9.8 critical | 23.3% | 2019-08-09 |
| CVE-2024-39914 | FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected… | Patch early | 9.8 critical | 23.2% | 2024-07-12 |
| CVE-2024-12209 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2… | Patch early | 9.8 critical | 23.2% | 2024-12-08 |
| CVE-2009-2367 | cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privi… | Patch early | 9.8 critical | 23.2% | 2009-07-08 |
| CVE-2016-8704 | An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary… | Patch early | 9.8 critical | 23.2% | 2017-01-06 |
| CVE-2018-13324 | Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host… | Patch early | 9.8 critical | 23.2% | 2018-11-26 |
| CVE-2023-28131 | A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the… | Patch early | 9.6 critical | 23.2% | 2023-04-24 |
| CVE-2022-47949 | The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitra… | Patch early | 9.8 critical | 23.1% | 2022-12-24 |
| CVE-2017-2885 | An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow… | Patch early | 9.8 critical | 23.1% | 2018-04-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt