CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,178 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-8309 | A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulner… | Patch early | 9.8 critical | 13.7% | 2024-10-29 |
| CVE-2016-1908 | The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-contro… | Patch early | 9.8 critical | 13.7% | 2017-04-11 |
| CVE-2022-46502 | Online Student Enrollment System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /student_enrollment/admin/… | Patch early | 9.8 critical | 13.7% | 2023-01-13 |
| CVE-2015-8668 | Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attackers to exe… | Patch early | 9.8 critical | 13.7% | 2016-01-08 |
| CVE-2021-33265 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… | Patch early | 9.8 critical | 13.7% | 2021-12-01 |
| CVE-2025-15471 | A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation… | Patch early | 9.8 critical | 13.7% | 2026-01-07 |
| CVE-2023-7095 | A vulnerability, which was classified as critical, has been found in Totolink A7100RU 7.4cu.2313_B20191024. Affected by this issue is the function mai… | Patch early | 9.8 critical | 13.7% | 2023-12-25 |
| CVE-2022-29328 | D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a stack overflow via the function checkvalidupgrade. | Patch early | 9.8 critical | 13.7% | 2022-05-10 |
| CVE-2022-29329 | D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a heap overflow via the devicename parameter in /goform/setDeviceSettings. | Patch early | 9.8 critical | 13.7% | 2022-05-10 |
| CVE-2008-3465 | Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 200… | Patch early | 9.8 critical | 13.7% | 2008-12-10 |
| CVE-2021-22987 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x be… | Patch early | 9.9 critical | 13.7% | 2021-03-31 |
| CVE-2018-4895 | An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier v… | Patch early | 9.8 critical | 13.7% | 2018-02-27 |
| CVE-2026-22844 | A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote c… | Patch early | 9.9 critical | 13.6% | 2026-01-20 |
| CVE-2017-5178 | An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and prior. Thes… | Patch early | 9.8 critical | 13.6% | 2017-03-08 |
| CVE-2021-27198 | An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in… | Patch early | 9.8 critical | 13.6% | 2021-02-26 |
| CVE-2024-3495 | The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and incl… | Patch early | 9.8 critical | 13.6% | 2024-05-22 |
| CVE-2022-32409 | A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to e… | Patch early | 9.8 critical | 13.6% | 2022-07-14 |
| CVE-2022-24995 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a De… | Patch early | 9.8 critical | 13.6% | 2022-03-10 |
| CVE-2016-4403 | A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to… | Patch early | 9.8 critical | 13.6% | 2018-08-06 |
| CVE-2026-23696 | Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allow… | Patch early | 9.9 critical | 13.6% | 2026-04-07 |
| CVE-2020-12110 | Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC2… | Patch early | 9.8 critical | 13.6% | 2020-05-04 |
| CVE-2020-35326 | SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0.6 via the… | Patch early | 9.8 critical | 13.6% | 2023-01-18 |
| CVE-2025-0890 | **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR… | Patch early | 9.8 critical | 13.5% | 2025-02-04 |
| CVE-2025-52689 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with administrator privileges by spo… | Patch early | 9.8 critical | 13.5% | 2025-07-16 |
| CVE-2022-45359 | Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress. | Patch early | 9.8 critical | 13.5% | 2022-12-06 |
| CVE-2022-34607 | H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /doping.asp. | Patch early | 9.8 critical | 13.5% | 2022-07-20 |
| CVE-2016-1000282 | Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command… | Patch early | 9.8 critical | 13.5% | 2019-02-05 |
| CVE-2024-39288 | A buffer overflow vulnerability exists in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted H… | Patch early | 9.1 critical | 13.5% | 2025-01-14 |
| CVE-2019-20445 | HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Enc… | Patch early | 9.1 critical | 13.5% | 2020-01-29 |
| CVE-2026-1056 | The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dir… | Patch early | 9.8 critical | 13.5% | 2026-01-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt