CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,092 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,706 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-12031 | Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal w… | Patch early | 9.8 critical | 19.8% | 2018-06-07 |
| CVE-2001-0249 | Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST comman… | Patch early | 9.8 critical | 19.7% | 2001-06-18 |
| CVE-2021-27177 | An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to bypass authentication by sending the decoded value of the GgpoZ… | Patch early | 9.8 critical | 19.7% | 2021-02-10 |
| CVE-2021-26102 | A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker t… | Patch early | 9.8 critical | 19.7% | 2024-12-19 |
| CVE-2017-18047 | Buffer Overflow in the FTP client in LabF nfsAxe 3.7 allows remote FTP servers to execute arbitrary code via a long reply. | Patch early | 9.8 critical | 19.7% | 2018-01-22 |
| CVE-2024-6457 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ‘woof_author’ paramete… | Patch early | 9.8 critical | 19.7% | 2024-07-16 |
| CVE-2019-9204 | SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands. | Patch early | 9.8 critical | 19.7% | 2019-03-28 |
| CVE-2023-27853 | NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute ar… | Patch early | 9.8 critical | 19.7% | 2023-03-10 |
| CVE-2020-11117 | u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in re… | Patch early | 9.8 critical | 19.7% | 2020-09-08 |
| CVE-2018-17934 | NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended dir… | Patch early | 9.8 critical | 19.7% | 2018-11-27 |
| CVE-2020-10567 | An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no… | Patch early | 9.8 critical | 19.6% | 2020-03-14 |
| CVE-2018-16287 | LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs. | Patch early | 9.8 critical | 19.6% | 2018-09-14 |
| CVE-2022-26187 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function. | Patch early | 9.8 critical | 19.6% | 2022-03-22 |
| CVE-2019-8287 | TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. This attac… | Patch early | 9.8 critical | 19.5% | 2019-10-29 |
| CVE-2019-10891 | An issue was discovered in D-Link DIR-806 devices. There is a command injection in function hnap_main, which calls system() without checking the param… | Patch early | 9.8 critical | 19.4% | 2019-09-06 |
| CVE-2025-43560 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary cod… | Patch early | 9.1 critical | 19.4% | 2025-05-13 |
| CVE-2025-58443 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vu… | Patch early | 9.1 critical | 19.4% | 2025-09-06 |
| CVE-2021-31800 | Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance ca… | Patch early | 9.8 critical | 19.4% | 2021-05-05 |
| CVE-2019-15683 | TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a536136e. This could possibly res… | Patch early | 9.8 critical | 19.4% | 2019-10-29 |
| CVE-2020-16137 | A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the credentials for the SS… | Patch early | 9.8 critical | 19.4% | 2020-08-12 |
| CVE-2022-46887 | Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter… | Patch early | 9.8 critical | 19.4% | 2023-01-19 |
| CVE-2022-32449 | TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function.… | Patch early | 9.8 critical | 19.4% | 2022-07-07 |
| CVE-2017-7658 | In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented wi… | Patch early | 9.8 critical | 19.4% | 2018-06-26 |
| CVE-2022-1366 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an at… | Patch early | 9.8 critical | 19.3% | 2022-05-02 |
| CVE-2022-1367 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an att… | Patch early | 9.8 critical | 19.3% | 2022-05-02 |
| CVE-2022-1378 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an… | Patch early | 9.8 critical | 19.3% | 2022-05-02 |
| CVE-2021-27166 | An issue was discovered on FiberHome HG6245D devices through RP2613. The password for the enable command is gpon. | Patch early | 9.8 critical | 19.3% | 2021-02-10 |
| CVE-2021-27172 | An issue was discovered on FiberHome HG6245D devices through RP2613. A hardcoded GEPON password for root is defined inside /etc/init.d/system-config.s… | Patch early | 9.8 critical | 19.3% | 2021-02-10 |
| CVE-2024-10386 | CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network acc… | Patch early | 9.8 critical | 19.3% | 2024-10-25 |
| CVE-2020-17438 | An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validate… | Patch early | 9.8 critical | 19.3% | 2020-12-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt