CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,075 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-45461 | FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitr… | Patch early | 9.8 critical | 21.7% | 2021-12-22 |
| CVE-2021-31932 | Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functio… | Patch early | 9.8 critical | 21.6% | 2022-02-11 |
| CVE-2024-29855 | Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator | Patch early | 9.0 critical | 21.6% | 2024-06-11 |
| CVE-2022-30450 | A Remote Code Execution (RCE) vulnerability exists in waimairen 9.1 via wx.php | Patch early | 9.8 critical | 21.6% | 2022-05-11 |
| CVE-2021-27078 | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch early | 9.1 critical | 21.6% | 2021-03-03 |
| CVE-2018-8540 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injec… | Patch early | 9.8 critical | 21.6% | 2018-12-12 |
| CVE-2017-5674 | A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a… | Patch early | 9.8 critical | 21.6% | 2017-03-13 |
| CVE-2018-16286 | LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limi… | Patch early | 9.8 critical | 21.5% | 2018-09-14 |
| CVE-2018-18006 | Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL… | Patch early | 9.8 critical | 21.5% | 2018-12-14 |
| CVE-2016-0132 | Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents… | Patch early | 9.8 critical | 21.5% | 2016-03-09 |
| CVE-2019-7267 | Linear eMerge 50P/5000P devices allow Cookie Path Traversal. | Patch early | 9.8 critical | 21.5% | 2019-07-02 |
| CVE-2019-12409 | The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh… | Patch early | 9.8 critical | 21.4% | 2019-11-18 |
| CVE-2022-26635 | PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disput… | Patch early | 9.8 critical | 21.4% | 2022-04-05 |
| CVE-2019-25224 | The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerabilit… | Patch early | 9.8 critical | 21.4% | 2025-07-25 |
| CVE-2021-43319 | Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality. | Patch early | 9.8 critical | 21.4% | 2021-11-30 |
| CVE-2022-33171 | The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-con… | Patch early | 9.8 critical | 21.4% | 2022-07-04 |
| CVE-2021-27144 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u c… | Patch early | 9.8 critical | 21.4% | 2021-02-10 |
| CVE-2021-22823 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user r… | Patch early | 9.1 critical | 21.4% | 2022-02-11 |
| CVE-2018-2879 | Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Authentication Engine). Supported versions that are af… | Patch early | 9.0 critical | 21.4% | 2018-04-19 |
| CVE-2018-8014 | The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are inse… | Patch early | 9.8 critical | 21.3% | 2018-05-16 |
| CVE-2018-1216 | A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell… | Patch early | 9.8 critical | 21.3% | 2018-03-08 |
| CVE-2018-8626 | A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS… | Patch early | 9.8 critical | 21.2% | 2018-12-12 |
| CVE-2016-9498 | ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by r… | Patch early | 9.8 critical | 21.2% | 2018-07-13 |
| CVE-2023-21692 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Patch early | 9.8 critical | 21.2% | 2023-02-14 |
| CVE-2017-18365 | The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arb… | Patch early | 9.8 critical | 21.2% | 2019-03-28 |
| CVE-2021-25641 | Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before… | Patch early | 9.8 critical | 21.2% | 2021-06-01 |
| CVE-2025-37924 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL w… | Patch early | 9.8 critical | 21.2% | 2025-05-20 |
| CVE-2022-3921 | The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could al… | Patch early | 9.8 critical | 21.2% | 2022-12-12 |
| CVE-2022-38308 | TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function cstesystem. T… | Patch early | 9.8 critical | 21.2% | 2022-09-14 |
| CVE-2020-11901 | The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response. | Patch early | 9.0 critical | 21.1% | 2020-06-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt