CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,178 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-18240 | In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute a… | Patch early | 9.8 critical | 14.3% | 2019-11-13 |
| CVE-2023-4596 | The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to th… | Patch early | 9.8 critical | 14.3% | 2023-08-30 |
| CVE-2025-2605 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse… | Patch early | 9.9 critical | 14.3% | 2025-05-02 |
| CVE-2015-5377 | Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appe… | Patch early | 9.8 critical | 14.3% | 2018-03-06 |
| CVE-2023-47253 | Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValo… | Patch early | 9.8 critical | 14.3% | 2023-11-06 |
| CVE-2018-11716 | An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Centr… | Patch early | 9.8 critical | 14.3% | 2018-07-16 |
| CVE-2019-2904 | Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11… | Patch early | 9.8 critical | 14.3% | 2019-10-16 |
| CVE-2022-38488 | logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter. | Patch early | 9.8 critical | 14.2% | 2022-12-14 |
| CVE-2023-27267 | Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with… | Patch early | 9.0 critical | 14.2% | 2023-04-11 |
| CVE-2022-3792 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allo… | Patch early | 9.8 critical | 14.2% | 2023-01-10 |
| CVE-2022-33174 | Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exp… | Patch early | 9.8 critical | 14.1% | 2022-06-13 |
| CVE-2023-39750 | D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vulnerability is exploited via a… | Patch early | 9.8 critical | 14.1% | 2023-08-21 |
| CVE-2017-8011 | EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all v… | Patch early | 9.8 critical | 14% | 2017-07-17 |
| CVE-2025-40599 | An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative priv… | Patch early | 9.1 critical | 14% | 2025-07-23 |
| CVE-2019-0195 | Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker foun… | Patch early | 9.8 critical | 14% | 2019-09-16 |
| CVE-2020-7356 | CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_inp… | Patch early | 10.0 critical | 14% | 2020-08-06 |
| CVE-2018-4924 | Adobe Dreamweaver CC versions 18.0 and earlier have an OS Command Injection vulnerability. Successful exploitation could lead to arbitrary code execut… | Patch early | 9.8 critical | 14% | 2018-05-19 |
| CVE-2023-45852 | In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell me… | Patch early | 9.8 critical | 14% | 2023-10-14 |
| CVE-2020-3716 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnera… | Patch early | 9.8 critical | 14% | 2020-01-29 |
| CVE-2026-4480 | A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print… | Patch early | 9.0 critical | 13.9% | 2026-05-26 |
| CVE-2021-29212 | A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versions 1.80, 1.81, 1.90 and 1.95.… | Patch early | 9.8 critical | 13.9% | 2021-11-01 |
| CVE-2020-27600 | HNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Router DIR-846 DIR-846 A1_100.26 allows remote attackers to execute arbitrary commands via sh… | Patch early | 9.8 critical | 13.9% | 2021-04-02 |
| CVE-2023-23560 | In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation. | Patch early | 9.8 critical | 13.9% | 2023-01-23 |
| CVE-2019-12419 | Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulner… | Patch early | 9.8 critical | 13.8% | 2019-11-06 |
| CVE-2022-27927 | A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue… | Patch early | 9.8 critical | 13.8% | 2022-04-19 |
| CVE-2017-7230 | A buffer overflow vulnerability in Disk Sorter Enterprise 9.5.12 and earlier allows remote attackers to execute arbitrary code via a GET request. | Patch early | 9.8 critical | 13.8% | 2017-03-22 |
| CVE-2023-20036 | A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges… | Patch early | 9.9 critical | 13.8% | 2024-11-15 |
| CVE-2022-40855 | Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This vulnerabili… | Patch early | 9.8 critical | 13.8% | 2022-09-23 |
| CVE-2023-34563 | netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication. | Patch early | 9.8 critical | 13.7% | 2023-06-20 |
| CVE-2023-31475 | An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requeste… | Patch early | 9.8 critical | 13.7% | 2023-05-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt