CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,121 CVEs
1,733 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-27143 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / user1234 credentials for an ISP. | Patch early | 9.8 critical | 16% | 2021-02-10 |
| CVE-2021-45837 | It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted inp… | Patch early | 9.8 critical | 16% | 2022-04-25 |
| CVE-2021-27170 | An issue was discovered on FiberHome HG6245D devices through RP2613. By default, there are no firewall rules for IPv6 connectivity, exposing the inter… | Patch early | 9.8 critical | 15.9% | 2021-02-10 |
| CVE-2022-34907 | An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to… | Patch early | 9.8 critical | 15.9% | 2022-07-25 |
| CVE-2021-46393 | There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly ret… | Patch early | 9.8 critical | 15.9% | 2022-03-04 |
| CVE-2022-1680 | An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10… | Patch early | 9.9 critical | 15.9% | 2022-06-06 |
| CVE-2017-11393 | Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable install… | Patch early | 9.8 critical | 15.9% | 2017-08-03 |
| CVE-2018-7665 | An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter to actions/beats_uploader.php… | Patch early | 9.8 critical | 15.9% | 2018-03-05 |
| CVE-2020-19213 | SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories. | Patch early | 9.8 critical | 15.9% | 2022-05-06 |
| CVE-2017-0903 | RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specification… | Patch early | 9.8 critical | 15.9% | 2017-10-11 |
| CVE-2023-36019 | Microsoft Power Platform Connector Spoofing Vulnerability | Patch early | 9.6 critical | 15.8% | 2023-12-12 |
| CVE-2019-17508 | On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable. | Patch early | 9.8 critical | 15.8% | 2019-10-11 |
| CVE-2023-20048 | A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to exe… | Patch early | 9.9 critical | 15.8% | 2023-11-01 |
| CVE-2021-27141 | An issue was discovered on FiberHome HG6245D devices through RP2613. Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7… | Patch early | 9.8 critical | 15.8% | 2021-02-10 |
| CVE-2024-34166 | An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially… | Patch early | 10.0 critical | 15.8% | 2025-01-14 |
| CVE-2021-38454 | A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite criti… | Patch early | 10.0 critical | 15.8% | 2021-10-12 |
| CVE-2003-0252 | Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of s… | Patch early | 9.8 critical | 15.8% | 2003-08-18 |
| CVE-2020-11857 | An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow rem… | Patch early | 9.8 critical | 15.8% | 2020-09-22 |
| CVE-2025-20265 | A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remot… | Patch early | 10.0 critical | 15.8% | 2025-08-14 |
| CVE-2016-4359 | Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 thr… | Patch early | 9.8 critical | 15.8% | 2016-06-08 |
| CVE-2023-0017 | An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use… | Patch early | 9.4 critical | 15.7% | 2023-01-10 |
| CVE-2018-1312 | In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly ge… | Patch early | 9.8 critical | 15.7% | 2018-03-26 |
| CVE-2024-51978 | An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenti… | Patch early | 9.8 critical | 15.7% | 2025-06-25 |
| CVE-2022-30453 | ShopWind <= 3.4.2 has a RCE vulnerability in Database.php | Patch early | 9.8 critical | 15.7% | 2022-05-11 |
| CVE-2021-40417 | When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitt… | Patch early | 9.8 critical | 15.7% | 2021-12-22 |
| CVE-2022-25082 | TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function.… | Patch early | 9.8 critical | 15.7% | 2022-02-24 |
| CVE-2023-4922 | The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter. | Patch early | 9.8 critical | 15.7% | 2023-11-27 |
| CVE-2020-5307 | PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category… | Patch early | 9.8 critical | 15.7% | 2020-01-07 |
| CVE-2024-48887 | A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a sp… | Patch early | 9.8 critical | 15.7% | 2025-04-08 |
| CVE-2014-1203 | The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in… | Patch early | 9.8 critical | 15.6% | 2017-10-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt