CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,084 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,705 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-2006 | HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, ak… | Patch early | 9.8 critical | 20.4% | 2016-04-21 |
| CVE-2016-2007 | HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, ak… | Patch early | 9.8 critical | 20.4% | 2016-04-21 |
| CVE-2018-18475 | Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload. | Patch early | 9.8 critical | 20.4% | 2018-10-23 |
| CVE-2024-39226 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.… | Patch early | 9.8 critical | 20.4% | 2024-08-06 |
| CVE-2016-9361 | An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.… | Patch early | 9.8 critical | 20.4% | 2017-02-13 |
| CVE-2019-9203 | Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API. | Patch early | 9.8 critical | 20.4% | 2019-03-28 |
| CVE-2026-22679 | Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devo… | Patch early | 9.8 critical | 20.4% | 2026-04-07 |
| CVE-2024-24576 | Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly esc… | Patch early | 10.0 critical | 20.3% | 2024-04-09 |
| CVE-2025-32583 | Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code Inclusion.This issue affects… | Patch early | 9.9 critical | 20.3% | 2025-04-17 |
| CVE-2022-22951 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command in… | Patch early | 9.1 critical | 20.3% | 2022-03-23 |
| CVE-2021-27146 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / CUadmin credentials for an ISP. | Patch early | 9.8 critical | 20.3% | 2021-02-10 |
| CVE-2021-27153 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded trueadmin / admintrue credentials for an IS… | Patch early | 9.8 critical | 20.3% | 2021-02-10 |
| CVE-2021-27154 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP. | Patch early | 9.8 critical | 20.3% | 2021-02-10 |
| CVE-2021-27155 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credential… | Patch early | 9.8 critical | 20.3% | 2021-02-10 |
| CVE-2019-12526 | An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remo… | Patch early | 9.8 critical | 20.3% | 2019-11-26 |
| CVE-2022-0591 | The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable… | Patch early | 9.1 critical | 20.2% | 2022-03-21 |
| CVE-2017-3167 | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication ph… | Patch early | 9.8 critical | 20.2% | 2017-06-20 |
| CVE-2023-31689 | In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and… | Patch early | 9.8 critical | 20.2% | 2023-05-22 |
| CVE-2024-22651 | There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04. | Patch early | 9.8 critical | 20.2% | 2024-01-24 |
| CVE-2022-45711 | IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools funct… | Patch early | 9.8 critical | 20.2% | 2022-12-23 |
| CVE-2024-29021 | Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable to a sandbox escape via Serve… | Patch early | 9.0 critical | 20.2% | 2024-04-18 |
| CVE-2024-39309 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and… | Patch early | 9.8 critical | 20.2% | 2024-07-01 |
| CVE-2021-22802 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on u… | Patch early | 9.8 critical | 20.2% | 2022-02-11 |
| CVE-2024-21334 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | Patch early | 9.8 critical | 20.2% | 2024-03-12 |
| CVE-2022-26082 | A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A speciall… | Patch early | 9.1 critical | 20.1% | 2022-05-25 |
| CVE-2022-1556 | The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for St… | Patch early | 9.8 critical | 20.1% | 2022-05-30 |
| CVE-2018-1000802 | Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Inj… | Patch early | 9.8 critical | 20.1% | 2018-09-18 |
| CVE-2021-3064 | A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-bas… | Patch early | 9.8 critical | 20.1% | 2021-11-10 |
| CVE-2022-38828 | TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi | Patch early | 9.8 critical | 20.1% | 2022-09-16 |
| CVE-2016-4510 | The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbitr… | Patch early | 9.1 critical | 20.1% | 2016-06-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt