CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,075 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-49001 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect succe… | Patch early | 9.8 critical | 21.1% | 2025-06-03 |
| CVE-2022-38352 | ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerabi… | Patch early | 9.8 critical | 21% | 2022-09-15 |
| CVE-2025-2828 | A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain… | Patch early | 10.0 critical | 21% | 2025-06-23 |
| CVE-2025-4978 | A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects an unknown part of the file /B… | Patch early | 9.8 critical | 21% | 2025-05-20 |
| CVE-2022-41657 | Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in fil… | Patch early | 9.8 critical | 20.9% | 2022-10-31 |
| CVE-2020-25111 | An issue was discovered in the IPv6 stack in Contiki through 3.0. There is an insufficient check for the IPv6 header length. This leads to Denial-of-S… | Patch early | 9.8 critical | 20.9% | 2020-12-11 |
| CVE-2020-10827 | A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code exec… | Patch early | 9.8 critical | 20.9% | 2020-03-26 |
| CVE-2020-10828 | A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code exec… | Patch early | 9.8 critical | 20.9% | 2020-03-26 |
| CVE-2014-7859 | Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-326 before 2… | Patch early | 9.8 critical | 20.9% | 2017-08-25 |
| CVE-2020-15893 | An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An att… | Patch early | 9.8 critical | 20.9% | 2020-07-22 |
| CVE-2021-45967 | An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path tr… | Patch early | 9.8 critical | 20.8% | 2022-03-18 |
| CVE-2010-1573 | Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages… | Patch early | 9.8 critical | 20.8% | 2010-06-10 |
| CVE-2022-27228 | In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code. | Patch early | 9.8 critical | 20.8% | 2022-03-22 |
| CVE-2024-21797 | A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP reque… | Patch early | 9.1 critical | 20.8% | 2025-01-14 |
| CVE-2024-36295 | A command execution vulnerability exists in the qos.cgi qos_sta() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request… | Patch early | 9.1 critical | 20.8% | 2025-01-14 |
| CVE-2018-19127 | A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable fil… | Patch early | 9.8 critical | 20.8% | 2018-11-09 |
| CVE-2017-5641 | Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. D… | Patch early | 9.8 critical | 20.7% | 2017-12-28 |
| CVE-2024-7332 | A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_c… | Patch early | 9.8 critical | 20.7% | 2024-08-01 |
| CVE-2023-24734 | An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image… | Patch early | 9.8 critical | 20.7% | 2023-03-06 |
| CVE-2026-1470 | n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated… | Patch early | 9.9 critical | 20.7% | 2026-01-27 |
| CVE-2023-28725 | General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary J… | Patch early | 9.1 critical | 20.6% | 2023-03-22 |
| CVE-2022-43775 | The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote… | Patch early | 9.8 critical | 20.6% | 2022-10-26 |
| CVE-2025-25291 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-s… | Patch early | 9.8 critical | 20.6% | 2025-03-12 |
| CVE-2025-43561 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code… | Patch early | 9.1 critical | 20.6% | 2025-05-13 |
| CVE-2022-27336 | Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php. | Patch early | 9.8 critical | 20.5% | 2022-04-27 |
| CVE-2017-6920 | Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely duri… | Patch early | 9.8 critical | 20.5% | 2018-08-06 |
| CVE-2023-45498 | VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability. | Patch early | 9.8 critical | 20.5% | 2023-10-27 |
| CVE-2022-24934 | wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry. | Patch early | 9.8 critical | 20.5% | 2022-03-23 |
| CVE-2016-4391 | A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0. | Patch early | 9.8 critical | 20.4% | 2018-08-06 |
| CVE-2016-2005 | HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, ak… | Patch early | 9.8 critical | 20.4% | 2016-04-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt