CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,185 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-8598 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could… | Patch early | 9.8 critical | 13.2% | 2020-03-18 |
| CVE-2018-9230 | In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters b… | Patch early | 9.8 critical | 13.2% | 2018-04-02 |
| CVE-2022-0735 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4,… | Patch early | 10.0 critical | 13.2% | 2022-03-28 |
| CVE-2017-5648 | While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.… | Patch early | 9.1 critical | 13.2% | 2017-04-17 |
| CVE-2023-49043 | Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the func… | Patch early | 9.8 critical | 13.2% | 2023-11-27 |
| CVE-2017-17731 | DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php. | Patch early | 9.8 critical | 13.2% | 2017-12-18 |
| CVE-2020-11264 | Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto… | Patch early | 9.1 critical | 13.2% | 2021-09-08 |
| CVE-2025-68668 | n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node… | Patch early | 9.9 critical | 13.2% | 2025-12-26 |
| CVE-2020-19625 | Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code,… | Patch early | 9.8 critical | 13.1% | 2021-03-26 |
| CVE-2021-22192 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary… | Patch early | 9.9 critical | 13.1% | 2021-03-24 |
| CVE-2017-11444 | Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array. | Patch early | 9.8 critical | 13.1% | 2017-07-19 |
| CVE-2022-0781 | The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (avail… | Patch early | 9.8 critical | 13.1% | 2022-05-23 |
| CVE-2022-25072 | TP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability… | Patch early | 9.8 critical | 13% | 2022-02-24 |
| CVE-2022-25073 | TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthenti… | Patch early | 9.8 critical | 13% | 2022-02-24 |
| CVE-2022-25074 | TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows una… | Patch early | 9.8 critical | 13% | 2022-02-24 |
| CVE-2016-8205 | A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 coul… | Patch early | 9.8 critical | 13% | 2017-01-14 |
| CVE-2020-12835 | An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacke… | Patch early | 9.8 critical | 13% | 2020-05-20 |
| CVE-2025-15029 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules)… | Patch early | 9.8 critical | 13% | 2026-01-05 |
| CVE-2025-61913 | Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in… | Patch early | 9.9 critical | 13% | 2025-10-08 |
| CVE-2018-9845 | Etherpad Lite before 1.6.4 is exploitable for admin access. | Patch early | 9.8 critical | 12.9% | 2018-04-29 |
| CVE-2018-19987 | D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-89… | Patch early | 9.8 critical | 12.9% | 2019-05-13 |
| CVE-2024-43491 | Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Wind… | Patch early | 9.8 critical | 12.9% | 2024-09-10 |
| CVE-2023-51092 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade. | Patch early | 9.8 critical | 12.9% | 2023-12-26 |
| CVE-2023-28324 | A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execut… | Patch early | 9.8 critical | 12.9% | 2023-07-01 |
| CVE-2022-36642 | A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users… | Patch early | 9.8 critical | 12.9% | 2022-09-02 |
| CVE-2019-3822 | libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`… | Patch early | 9.8 critical | 12.9% | 2019-02-06 |
| CVE-2020-28926 | ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP… | Patch early | 9.8 critical | 12.9% | 2020-11-30 |
| CVE-2018-5393 | The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (… | Patch early | 9.8 critical | 12.9% | 2018-09-28 |
| CVE-2022-1768 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied d… | Patch early | 9.8 critical | 12.9% | 2022-06-13 |
| CVE-2025-52906 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injectio… | Patch early | 9.8 critical | 12.8% | 2025-09-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt