CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,121 CVEs
1,733 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-43931 | Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers… | Patch early | 10.0 critical | 16.8% | 2023-01-03 |
| CVE-2020-29227 | An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file w… | Patch early | 9.8 critical | 16.8% | 2020-12-14 |
| CVE-2022-1660 | The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker… | Patch early | 9.8 critical | 16.8% | 2022-06-02 |
| CVE-2013-0022 | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers a… | Patch early | 9.0 critical | 16.8% | 2013-02-13 |
| CVE-2022-29904 | The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' a… | Patch early | 9.8 critical | 16.8% | 2022-04-29 |
| CVE-2016-4438 | The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression. | Patch early | 9.8 critical | 16.7% | 2016-07-04 |
| CVE-2018-7074 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT 7.3 E0506P07. The vulnerability was resolved in i… | Patch early | 9.8 critical | 16.7% | 2018-08-06 |
| CVE-2017-8990 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Service Manager (WSM) Software earlier than v… | Patch early | 9.8 critical | 16.7% | 2018-08-06 |
| CVE-2013-10069 | The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command inj… | Patch early | 9.8 critical | 16.7% | 2025-08-05 |
| CVE-2024-2056 | Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon… | Patch early | 9.8 critical | 16.7% | 2024-03-05 |
| CVE-2025-48148 | Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Using… | Patch early | 10.0 critical | 16.7% | 2025-08-20 |
| CVE-2017-5340 | Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attack… | Patch early | 9.8 critical | 16.7% | 2017-01-11 |
| CVE-2017-13067 | QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3… | Patch early | 9.8 critical | 16.7% | 2017-09-14 |
| CVE-2018-13350 | SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter. | Patch early | 9.8 critical | 16.7% | 2018-11-27 |
| CVE-2021-28918 | Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SS… | Patch early | 9.1 critical | 16.7% | 2021-04-01 |
| CVE-2016-0856 | Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors. | Patch early | 9.8 critical | 16.7% | 2016-01-15 |
| CVE-2023-5642 | Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive informat… | Patch early | 9.8 critical | 16.7% | 2023-10-18 |
| CVE-2017-16846 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter. | Patch early | 9.8 critical | 16.6% | 2017-11-16 |
| CVE-2017-16847 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView ac… | Patch early | 9.8 critical | 16.6% | 2017-11-16 |
| CVE-2017-16849 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter. | Patch early | 9.8 critical | 16.6% | 2017-11-16 |
| CVE-2017-16850 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfil… | Patch early | 9.8 critical | 16.6% | 2017-11-16 |
| CVE-2017-16851 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter. | Patch early | 9.8 critical | 16.6% | 2017-11-16 |
| CVE-2019-11400 | An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. A buffer overflow occurs through the get_set… | Patch early | 9.8 critical | 16.6% | 2019-12-18 |
| CVE-2023-25234 | Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface. | Patch early | 9.8 critical | 16.6% | 2023-02-27 |
| CVE-2016-7124 | ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause… | Patch early | 9.8 critical | 16.6% | 2016-09-12 |
| CVE-2024-8669 | The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backup… | Patch early | 9.1 critical | 16.6% | 2024-09-14 |
| CVE-2023-47207 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local admin… | Patch early | 9.8 critical | 16.6% | 2023-11-30 |
| CVE-2019-10082 | In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during co… | Patch early | 9.1 critical | 16.5% | 2019-09-26 |
| CVE-2017-5821 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | Patch early | 9.8 critical | 16.5% | 2018-02-15 |
| CVE-2024-39205 | An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request. | Patch early | 9.8 critical | 16.5% | 2024-10-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt