CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,116 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-22980 | A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that… | Patch early | 9.8 critical | 17.8% | 2022-06-23 |
| CVE-2021-27171 | An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to start a Linux telnetd as root on port 26/tcp by using the CLI i… | Patch early | 9.8 critical | 17.8% | 2021-02-10 |
| CVE-2024-38366 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real ema… | Patch early | 10.0 critical | 17.8% | 2024-07-01 |
| CVE-2017-15708 | In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases… | Patch early | 9.8 critical | 17.7% | 2017-12-11 |
| CVE-2016-5640 | Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to e… | Patch early | 9.8 critical | 17.7% | 2016-08-03 |
| CVE-2021-34746 | A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) coul… | Patch early | 9.8 critical | 17.7% | 2021-09-02 |
| CVE-2024-31214 | Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload… | Patch early | 9.6 critical | 17.6% | 2024-04-10 |
| CVE-2022-32995 | Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function. | Patch early | 9.8 critical | 17.6% | 2022-06-27 |
| CVE-2021-26877 | Windows DNS Server Remote Code Execution Vulnerability | Patch early | 9.8 critical | 17.6% | 2021-03-11 |
| CVE-2024-10456 | Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, w… | Patch early | 9.8 critical | 17.6% | 2024-10-30 |
| CVE-2025-61686 | React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node p… | Patch early | 9.1 critical | 17.6% | 2026-01-10 |
| CVE-2012-4787 | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that tri… | Patch early | 9.0 critical | 17.6% | 2012-12-12 |
| CVE-2023-27394 | Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute a… | Patch early | 9.8 critical | 17.6% | 2023-03-28 |
| CVE-2025-8723 | The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization… | Patch early | 9.8 critical | 17.6% | 2025-08-19 |
| CVE-2021-43527 | NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signat… | Patch early | 9.8 critical | 17.6% | 2021-12-08 |
| CVE-2021-45420 | Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi… | Patch early | 9.8 critical | 17.6% | 2022-02-14 |
| CVE-2022-31267 | Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile data field, such as an emailAddr… | Patch early | 9.8 critical | 17.5% | 2022-05-21 |
| CVE-2024-21591 | An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attac… | Patch early | 9.8 critical | 17.5% | 2024-01-12 |
| CVE-2019-6446 | An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via… | Patch early | 9.8 critical | 17.5% | 2019-01-16 |
| CVE-2023-36397 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | Patch early | 9.8 critical | 17.5% | 2023-11-14 |
| CVE-2025-45797 | TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the N… | Patch early | 9.8 critical | 17.5% | 2025-05-08 |
| CVE-2022-29632 | An arbitrary file upload vulnerability in the component /course/api/upload/pic of Roncoo Education v9.0.0 allows attackers to execute arbitrary code v… | Patch early | 9.8 critical | 17.5% | 2022-05-26 |
| CVE-2022-30808 | elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php. | Patch early | 9.8 critical | 17.5% | 2022-06-02 |
| CVE-2019-7838 | ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Succe… | Patch early | 9.8 critical | 17.4% | 2019-06-12 |
| CVE-2021-33357 | A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contai… | Patch early | 9.8 critical | 17.4% | 2021-06-09 |
| CVE-2025-35996 | KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API end… | Patch early | 9.0 critical | 17.4% | 2025-05-01 |
| CVE-2024-55547 | SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e. | Patch early | 9.8 critical | 17.4% | 2024-12-10 |
| CVE-2024-39760 | Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially cr… | Patch early | 10.0 critical | 17.4% | 2025-01-14 |
| CVE-2020-24916 | CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection. | Patch early | 9.8 critical | 17.4% | 2020-09-09 |
| CVE-2018-1285 | Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks… | Patch early | 9.8 critical | 17.4% | 2020-05-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt