CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,092 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,706 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-44088 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION. | Patch early | 9.8 critical | 20.1% | 2022-11-10 |
| CVE-2022-29592 | Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route). | Patch early | 9.8 critical | 20.1% | 2022-05-05 |
| CVE-2025-44084 | D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggerin… | Patch early | 9.8 critical | 20.1% | 2025-05-20 |
| CVE-2017-8658 | A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engi… | Patch early | 9.8 critical | 20.1% | 2017-08-11 |
| CVE-2020-6637 | openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php. | Patch early | 9.8 critical | 20.1% | 2020-08-24 |
| CVE-2023-34747 | File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload. | Patch early | 9.8 critical | 20% | 2023-06-14 |
| CVE-2019-15606 | Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons | Patch early | 9.8 critical | 20% | 2020-02-07 |
| CVE-2016-3586 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers… | Patch early | 9.8 critical | 20% | 2016-07-21 |
| CVE-2018-14701 | System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execu… | Patch early | 9.8 critical | 20% | 2018-12-03 |
| CVE-2018-19510 | subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header. | Patch early | 9.8 critical | 20% | 2019-03-21 |
| CVE-2022-31874 | ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface. | Patch early | 9.8 critical | 20% | 2022-06-17 |
| CVE-2019-8600 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.… | Patch early | 9.8 critical | 20% | 2019-12-18 |
| CVE-2017-3169 | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_conn… | Patch early | 9.8 critical | 20% | 2017-06-20 |
| CVE-2024-42448 | From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code E… | Patch early | 9.9 critical | 19.9% | 2024-12-12 |
| CVE-2020-8597 | eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. | Patch early | 9.8 critical | 19.9% | 2020-02-03 |
| CVE-2024-0087 | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists,… | Patch early | 9.0 critical | 19.9% | 2024-05-14 |
| CVE-2024-33344 | D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arb… | Patch early | 9.8 critical | 19.9% | 2024-04-26 |
| CVE-2022-23357 | mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir. | Patch early | 9.1 critical | 19.9% | 2022-02-03 |
| CVE-2020-13925 | Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whil… | Patch early | 9.8 critical | 19.9% | 2020-07-14 |
| CVE-2016-8705 | Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary prot… | Patch early | 9.8 critical | 19.9% | 2017-01-06 |
| CVE-2025-66398 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the int… | Patch early | 9.6 critical | 19.9% | 2026-01-01 |
| CVE-2021-27165 | An issue was discovered on FiberHome HG6245D devices through RP2613. The telnet daemon on port 23/tcp can be abused with the gpon/gpon credentials. | Patch early | 9.8 critical | 19.8% | 2021-02-10 |
| CVE-2021-27168 | An issue was discovered on FiberHome HG6245D devices through RP2613. There is a 6GFJdY4aAuUKJjdtSn7d password for the rdsadmin account. | Patch early | 9.8 critical | 19.8% | 2021-02-10 |
| CVE-2021-27169 | An issue was discovered on FiberHome AN5506-04-FA devices with firmware RP2631. There is a gepon password for the gepon account. | Patch early | 9.8 critical | 19.8% | 2021-02-10 |
| CVE-2021-41163 | Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution.… | Patch early | 10.0 critical | 19.8% | 2021-10-20 |
| CVE-2021-27150 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng4201… | Patch early | 9.8 critical | 19.8% | 2021-02-10 |
| CVE-2018-7489 | FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an inc… | Patch early | 9.8 critical | 19.8% | 2018-02-26 |
| CVE-2022-20695 | A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to… | Patch early | 10.0 critical | 19.8% | 2022-04-15 |
| CVE-2021-38390 | A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior… | Patch early | 9.8 critical | 19.8% | 2021-08-30 |
| CVE-2023-24775 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php. | Patch early | 9.8 critical | 19.8% | 2023-03-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt