CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,121 CVEs
1,733 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-2314 | The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site. | Patch early | 9.8 critical | 16.5% | 2022-08-15 |
| CVE-2025-14705 | A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulatio… | Patch early | 9.8 critical | 16.5% | 2025-12-15 |
| CVE-2023-36812 | OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing… | Patch early | 9.8 critical | 16.5% | 2023-06-30 |
| CVE-2024-41110 | Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Dock… | Patch early | 9.9 critical | 16.5% | 2024-07-24 |
| CVE-2021-27132 | SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition heade… | Patch early | 9.8 critical | 16.5% | 2021-02-27 |
| CVE-2019-14901 | A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows… | Patch early | 9.8 critical | 16.5% | 2019-11-29 |
| CVE-2020-9015 | Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow attackers t… | Patch early | 9.8 critical | 16.5% | 2020-02-20 |
| CVE-2020-1948 | This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or meth… | Patch early | 9.8 critical | 16.4% | 2020-07-14 |
| CVE-2021-4374 | The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missi… | Patch early | 9.1 critical | 16.4% | 2023-06-07 |
| CVE-2016-4402 | A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to… | Patch early | 9.8 critical | 16.4% | 2018-08-06 |
| CVE-2020-28187 | Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within… | Patch early | 9.8 critical | 16.4% | 2020-12-24 |
| CVE-2015-4643 | Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP ser… | Patch early | 9.8 critical | 16.3% | 2016-05-16 |
| CVE-2024-51818 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Product Designer fancy-product-des… | Patch early | 9.3 critical | 16.3% | 2025-01-21 |
| CVE-2015-9499 | The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive. | Patch early | 9.8 critical | 16.3% | 2019-10-22 |
| CVE-2017-5983 | The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers… | Patch early | 9.8 critical | 16.2% | 2017-04-10 |
| CVE-2023-42657 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker could leverage this vulnerabil… | Patch early | 9.9 critical | 16.2% | 2023-09-27 |
| CVE-2022-31830 | Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php. | Patch early | 9.1 critical | 16.2% | 2022-06-09 |
| CVE-2019-13990 | initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. | Patch early | 9.8 critical | 16.2% | 2019-07-26 |
| CVE-2021-34187 | main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter. | Patch early | 9.8 critical | 16.2% | 2021-06-28 |
| CVE-2023-33532 | There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges,… | Patch early | 9.8 critical | 16.2% | 2023-06-06 |
| CVE-2020-28032 | WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. | Patch early | 9.8 critical | 16.1% | 2020-11-02 |
| CVE-2025-44823 | Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/syst… | Patch early | 9.9 critical | 16.1% | 2025-10-07 |
| CVE-2021-28809 | An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attacke… | Patch early | 9.8 critical | 16.1% | 2021-07-08 |
| CVE-2018-14829 | Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CI… | Patch early | 9.8 critical | 16.1% | 2018-09-20 |
| CVE-2025-54381 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file up… | Patch early | 9.9 critical | 16.1% | 2025-07-29 |
| CVE-2010-5333 | The web server in Integard Pro and Home before 2.0.0.9037 and 2.2.x before 2.2.0.9037 has a buffer overflow via a long password in an administration l… | Patch early | 9.8 critical | 16% | 2019-09-13 |
| CVE-2021-42667 | A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can l… | Patch early | 9.8 critical | 16% | 2021-11-05 |
| CVE-2018-1163 | This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specific flaw… | Patch early | 9.8 critical | 16% | 2018-02-08 |
| CVE-2020-29047 | The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the… | Patch early | 9.8 critical | 16% | 2021-03-03 |
| CVE-2023-29778 | GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread. | Patch early | 9.8 critical | 16% | 2023-05-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt