CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,074 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-27151 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP. | Patch early | 9.8 critical | 23% | 2021-02-10 |
| CVE-2021-27152 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded awnfibre / fibre@dm!n credentials for an IS… | Patch early | 9.8 critical | 23% | 2021-02-10 |
| CVE-2021-27159 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP. | Patch early | 9.8 critical | 23% | 2021-02-10 |
| CVE-2021-27163 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / tele1234 credentials for an ISP. | Patch early | 9.8 critical | 23% | 2021-02-10 |
| CVE-2019-12928 | The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code exec… | Patch early | 9.8 critical | 23% | 2019-06-24 |
| CVE-2022-23676 | A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; Aruba… | Patch early | 9.8 critical | 23% | 2022-05-10 |
| CVE-2024-43917 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows… | Patch early | 9.3 critical | 23% | 2024-08-29 |
| CVE-2024-29943 | An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerabil… | Patch early | 9.8 critical | 22.9% | 2024-03-22 |
| CVE-2023-27076 | Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter. | Patch early | 9.8 critical | 22.9% | 2023-04-10 |
| CVE-2020-7048 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the i… | Patch early | 9.1 critical | 22.9% | 2020-01-16 |
| CVE-2025-43984 | An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211). They are vulnerable… | Patch early | 9.8 critical | 22.9% | 2025-08-14 |
| CVE-2022-29009 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows… | Patch early | 9.8 critical | 22.9% | 2022-05-11 |
| CVE-2020-28070 | SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via… | Patch early | 9.8 critical | 22.9% | 2020-12-23 |
| CVE-2018-13354 | System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter. | Patch early | 9.8 critical | 22.9% | 2018-11-27 |
| CVE-2024-23625 | A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit thi… | Patch early | 9.6 critical | 22.8% | 2024-01-26 |
| CVE-2024-37186 | An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTT… | Patch early | 9.1 critical | 22.8% | 2025-01-14 |
| CVE-2024-29974 | ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before … | Patch early | 9.8 critical | 22.8% | 2024-06-04 |
| CVE-2016-6808 | Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42. | Patch early | 9.8 critical | 22.7% | 2017-04-12 |
| CVE-2022-28956 | An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload. | Patch early | 9.8 critical | 22.7% | 2022-05-18 |
| CVE-2021-39378 | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL… | Patch early | 9.8 critical | 22.7% | 2021-09-01 |
| CVE-2025-9501 | The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated u… | Patch early | 9.0 critical | 22.6% | 2025-11-17 |
| CVE-2023-46042 | An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo(). | Patch early | 9.8 critical | 22.6% | 2023-10-19 |
| CVE-2022-28557 | There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, w… | Patch early | 9.8 critical | 22.6% | 2022-05-04 |
| CVE-2017-18371 | The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded… | Patch early | 9.8 critical | 22.5% | 2019-05-02 |
| CVE-2018-8327 | A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This… | Patch early | 9.8 critical | 22.5% | 2018-07-11 |
| CVE-2017-14980 | Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login. | Patch early | 9.8 critical | 22.5% | 2017-10-10 |
| CVE-2022-34555 | TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is exploited via a crafted packet… | Patch early | 9.8 critical | 22.5% | 2022-07-28 |
| CVE-2022-26272 | A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted string written to the file app… | Patch early | 9.8 critical | 22.5% | 2022-03-24 |
| CVE-2019-10232 | Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php. | Patch early | 9.8 critical | 22.4% | 2019-03-27 |
| CVE-2024-47908 | OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achie… | Patch early | 9.1 critical | 22.3% | 2025-02-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt