CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,074 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-19365 | The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted… | Patch early | 9.1 critical | 22.3% | 2019-03-21 |
| CVE-2025-54261 | ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Travers… | Patch early | 10.0 critical | 22.2% | 2025-09-09 |
| CVE-2017-5804 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. | Patch early | 9.8 critical | 22.2% | 2018-02-15 |
| CVE-2017-5805 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. | Patch early | 9.8 critical | 22.2% | 2018-02-15 |
| CVE-2017-5806 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. | Patch early | 9.8 critical | 22.2% | 2018-02-15 |
| CVE-2025-25014 | A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints. | Patch early | 9.1 critical | 22.2% | 2025-05-06 |
| CVE-2022-31259 | The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configure… | Patch early | 9.8 critical | 22.2% | 2022-05-21 |
| CVE-2021-24094 | Windows TCP/IP Remote Code Execution Vulnerability | Patch early | 9.8 critical | 22.1% | 2021-02-25 |
| CVE-2022-36572 | Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /upload/admin… | Patch early | 9.8 critical | 22% | 2022-08-29 |
| CVE-2023-2479 | OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4. | Patch early | 9.8 critical | 22% | 2023-05-02 |
| CVE-2025-2005 | The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the… | Patch early | 9.8 critical | 22% | 2025-04-02 |
| CVE-2015-7919 | SearchBlox 8.3 before 8.3.1 allows remote attackers to write to the config file, and consequently cause a denial of service (application crash), via u… | Patch early | 10.0 critical | 22% | 2015-12-21 |
| CVE-2025-55346 | User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS… | Patch early | 9.8 critical | 22% | 2025-08-14 |
| CVE-2021-22931 | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host n… | Patch early | 9.8 critical | 22% | 2021-08-16 |
| CVE-2022-23389 | PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter. | Patch early | 9.8 critical | 22% | 2022-02-14 |
| CVE-2023-52440 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->Sessio… | Patch early | 9.8 critical | 21.9% | 2024-02-21 |
| CVE-2017-5807 | A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found. | Patch early | 9.8 critical | 21.9% | 2018-02-15 |
| CVE-2024-1283 | Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted H… | Patch early | 9.8 critical | 21.9% | 2024-02-07 |
| CVE-2021-46704 | In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts a… | Patch early | 9.8 critical | 21.9% | 2022-03-06 |
| CVE-2022-1390 | The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated a… | Patch early | 9.8 critical | 21.9% | 2022-04-25 |
| CVE-2018-17879 | An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several i… | Patch early | 9.8 critical | 21.9% | 2023-10-26 |
| CVE-2023-0104 | The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an… | Patch early | 9.3 critical | 21.8% | 2023-02-22 |
| CVE-2017-14135 | enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute arbitrar… | Patch early | 9.8 critical | 21.8% | 2017-09-04 |
| CVE-2023-3824 | In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insuff… | Patch early | 9.4 critical | 21.8% | 2023-08-11 |
| CVE-2022-40471 | Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload function… | Patch early | 9.8 critical | 21.8% | 2022-10-31 |
| CVE-2022-37128 | In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end. | Patch early | 9.8 critical | 21.7% | 2022-08-31 |
| CVE-2022-31827 | MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php. | Patch early | 9.1 critical | 21.7% | 2022-06-09 |
| CVE-2022-37134 | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base6… | Patch early | 9.8 critical | 21.7% | 2022-08-22 |
| CVE-2026-23550 | Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: fro… | Patch early | 9.8 critical | 21.7% | 2026-01-14 |
| CVE-2019-1373 | A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Rem… | Patch early | 9.8 critical | 21.7% | 2019-11-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt