CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,133 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-13585 | The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 has a Buffer Overflow via a forged HTTP request. | Patch early | 9.8 critical | 14.7% | 2019-07-17 |
| CVE-2020-24148 | Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read… | Patch early | 9.1 critical | 14.7% | 2021-07-07 |
| CVE-2018-8088 | org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via… | Patch early | 9.8 critical | 14.7% | 2018-03-20 |
| CVE-2019-18655 | File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnerability. An unauthenticated att… | Patch early | 9.8 critical | 14.7% | 2019-11-12 |
| CVE-2021-24285 | The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and una… | Patch early | 9.8 critical | 14.7% | 2021-05-14 |
| CVE-2017-0223 | A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scrip… | Patch early | 9.8 critical | 14.7% | 2017-05-15 |
| CVE-2022-31788 | IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname. | Patch early | 9.8 critical | 14.7% | 2022-06-10 |
| CVE-2024-33512 | There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to unauthenticated remote code e… | Patch early | 9.8 critical | 14.6% | 2024-05-01 |
| CVE-2021-27167 | An issue was discovered on FiberHome HG6245D devices through RP2613. There is a password of four hexadecimal characters for the admin account. These c… | Patch early | 9.8 critical | 14.6% | 2021-02-10 |
| CVE-2022-28531 | Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field. | Patch early | 9.8 critical | 14.6% | 2022-05-20 |
| CVE-2019-11395 | A buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long string, as demonstrated by SMTP RCPT TO, POP3 USER,… | Patch early | 9.8 critical | 14.6% | 2019-04-22 |
| CVE-2024-33511 | There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticated remote code execution by sen… | Patch early | 9.8 critical | 14.6% | 2024-05-01 |
| CVE-2020-18568 | The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution. | Patch early | 9.8 critical | 14.6% | 2021-02-02 |
| CVE-2015-8812 | drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to exe… | Patch early | 9.8 critical | 14.5% | 2016-04-27 |
| CVE-2023-47248 | Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is v… | Patch early | 9.8 critical | 14.5% | 2023-11-09 |
| CVE-2023-23369 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… | Patch early | 9.0 critical | 14.5% | 2023-11-03 |
| CVE-2021-3958 | Improper Handling of Parameters vulnerability in Ipack Automation Systems Ipack SCADA Software allows : Blind SQL Injection.This issue affects Ipack S… | Patch early | 9.8 critical | 14.5% | 2021-11-16 |
| CVE-2024-44400 | A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the… | Patch early | 9.8 critical | 14.5% | 2024-09-04 |
| CVE-2021-24175 | The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication,… | Patch early | 9.8 critical | 14.5% | 2021-04-05 |
| CVE-2017-3081 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability during internal computation caused by multiple dis… | Patch early | 9.8 critical | 14.4% | 2017-06-20 |
| CVE-2017-3083 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the Primetime SDK functionality related to the… | Patch early | 9.8 critical | 14.4% | 2017-06-20 |
| CVE-2024-39225 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.… | Patch early | 9.8 critical | 14.4% | 2024-08-06 |
| CVE-2022-23329 | A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading… | Patch early | 9.8 critical | 14.4% | 2022-02-04 |
| CVE-2015-3188 | The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors. | Patch early | 9.8 critical | 14.4% | 2017-01-13 |
| CVE-2022-22897 | A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for Pr… | Patch early | 9.8 critical | 14.4% | 2022-08-29 |
| CVE-2025-6507 | A vulnerability in the h2oai/h2o-3 repository allows attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code exe… | Patch early | 9.8 critical | 14.4% | 2025-09-01 |
| CVE-2022-43604 | An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit… | Patch early | 10.0 critical | 14.4% | 2023-03-16 |
| CVE-2022-43605 | An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit… | Patch early | 10.0 critical | 14.4% | 2023-03-16 |
| CVE-2024-57684 | An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service… | Patch early | 9.8 critical | 14.4% | 2025-01-16 |
| CVE-2020-10619 | An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control. | Patch early | 9.1 critical | 14.3% | 2020-04-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt