CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,133 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-26020 | An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbit… | Patch early | 9.6 critical | 15.2% | 2024-07-22 |
| CVE-2014-7857 | D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and D… | Patch early | 9.8 critical | 15.2% | 2017-08-25 |
| CVE-2014-7858 | The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the username co… | Patch early | 9.8 critical | 15.2% | 2017-08-25 |
| CVE-2024-26305 | There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending speciall… | Patch early | 9.8 critical | 15.2% | 2024-05-01 |
| CVE-2025-54322 | Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and… | Patch early | 10.0 critical | 15.1% | 2025-12-27 |
| CVE-2017-16848 | Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter. | Patch early | 9.8 critical | 15.1% | 2017-11-16 |
| CVE-2022-30521 | The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09… | Patch early | 9.8 critical | 15.1% | 2022-06-02 |
| CVE-2018-1149 | cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP requests. | Patch early | 9.8 critical | 15.1% | 2018-09-19 |
| CVE-2018-15127 | LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension… | Patch early | 9.8 critical | 15.1% | 2018-12-19 |
| CVE-2023-20238 | A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Pla… | Patch early | 10.0 critical | 15.1% | 2023-09-06 |
| CVE-2022-1391 | The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could le… | Patch early | 9.8 critical | 15.1% | 2022-04-25 |
| CVE-2022-37113 | Bluecms 1.6 has SQL injection in line 132 of admin/area.php | Patch early | 9.8 critical | 15% | 2022-08-23 |
| CVE-2021-27156 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains credentials for an ISP that equal the last part of the MA… | Patch early | 9.8 critical | 15% | 2021-02-10 |
| CVE-2021-27157 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 888888 credentials for an ISP. | Patch early | 9.8 critical | 15% | 2021-02-10 |
| CVE-2024-10392 | The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_u… | Patch early | 9.8 critical | 15% | 2024-10-31 |
| CVE-2020-4212 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP c… | Patch early | 9.8 critical | 15% | 2020-02-24 |
| CVE-2023-28765 | An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to… | Patch early | 9.8 critical | 14.9% | 2023-04-11 |
| CVE-2021-32941 | Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows… | Patch early | 9.4 critical | 14.9% | 2022-05-23 |
| CVE-2017-14100 | In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert… | Patch early | 9.8 critical | 14.9% | 2017-09-02 |
| CVE-2022-0747 | The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld… | Patch early | 9.8 critical | 14.9% | 2022-03-21 |
| CVE-2017-7657 | In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfe… | Patch early | 9.8 critical | 14.9% | 2018-06-26 |
| CVE-2016-5003 | The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialize… | Patch early | 9.8 critical | 14.9% | 2017-10-27 |
| CVE-2024-3596 | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject,… | Patch early | 9.0 critical | 14.9% | 2024-07-09 |
| CVE-2024-38368 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pr… | Patch early | 9.3 critical | 14.9% | 2024-07-01 |
| CVE-2021-1388 | A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthentica… | Patch early | 10.0 critical | 14.8% | 2021-02-24 |
| CVE-2022-26245 | Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go. | Patch early | 9.8 critical | 14.8% | 2022-03-27 |
| CVE-2016-8339 | A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability e… | Patch early | 9.8 critical | 14.8% | 2016-10-28 |
| CVE-2025-53693 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecor… | Patch early | 9.8 critical | 14.8% | 2025-09-03 |
| CVE-2022-0434 | The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST e… | Patch early | 9.8 critical | 14.8% | 2022-03-07 |
| CVE-2016-4404 | A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to… | Patch early | 9.8 critical | 14.8% | 2018-08-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt