CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,212 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-46009 | In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set… | Patch early | 9.8 critical | 12.5% | 2022-03-30 |
| CVE-2024-28253 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamle… | Patch early | 9.4 critical | 12.5% | 2024-03-15 |
| CVE-2017-16844 | Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (appl… | Patch early | 9.8 critical | 12.5% | 2017-11-16 |
| CVE-2022-38827 | TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi | Patch early | 9.8 critical | 12.5% | 2022-09-16 |
| CVE-2022-22806 | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed con… | Patch early | 9.8 critical | 12.5% | 2022-03-09 |
| CVE-2023-34659 | jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface. | Patch early | 9.8 critical | 12.5% | 2023-06-16 |
| CVE-2024-37080 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter S… | Patch early | 9.8 critical | 12.5% | 2024-06-18 |
| CVE-2019-7297 | An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitr… | Patch early | 9.8 critical | 12.5% | 2019-01-31 |
| CVE-2025-41656 | An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED… | Patch early | 10.0 critical | 12.5% | 2025-07-01 |
| CVE-2024-36258 | A stack-based buffer overflow vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A spe… | Patch early | 10.0 critical | 12.4% | 2025-01-14 |
| CVE-2021-27314 | SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter… | Patch early | 9.8 critical | 12.4% | 2021-03-05 |
| CVE-2015-7705 | The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of c… | Patch early | 9.8 critical | 12.4% | 2017-08-07 |
| CVE-2022-22978 | In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be by… | Patch early | 9.8 critical | 12.4% | 2022-05-19 |
| CVE-2018-7076 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) prior to iMC PLAT 7.3 E0605P04. | Patch early | 9.8 critical | 12.3% | 2018-10-17 |
| CVE-2024-32641 | Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code e… | Patch early | 9.8 critical | 12.3% | 2025-12-03 |
| CVE-2018-3786 | A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument. | Patch early | 9.8 critical | 12.3% | 2018-08-24 |
| CVE-2018-5924 | A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a stack… | Patch early | 9.8 critical | 12.2% | 2018-08-13 |
| CVE-2020-4448 | IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with… | Patch early | 9.8 critical | 12.2% | 2020-06-05 |
| CVE-2022-1574 | The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result,… | Patch early | 9.8 critical | 12.2% | 2022-06-27 |
| CVE-2020-36962 | Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas du… | Patch early | 9.8 critical | 12.2% | 2026-01-28 |
| CVE-2015-1832 | XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows… | Patch early | 9.1 critical | 12.2% | 2016-10-03 |
| CVE-2019-15678 | TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appe… | Patch early | 9.8 critical | 12.2% | 2019-10-29 |
| CVE-2021-39238 | Certain HP Enterprise LaserJet, HP LaserJet Managed, HP Enterprise PageWide, HP PageWide Managed products may be vulnerable to potential buffer overfl… | Patch early | 9.8 critical | 12.1% | 2021-11-03 |
| CVE-2019-0721 | A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticat… | Patch early | 9.1 critical | 12.1% | 2019-11-12 |
| CVE-2020-35338 | The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a… | Patch early | 9.8 critical | 12.1% | 2020-12-14 |
| CVE-2018-18312 | Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | Patch early | 9.8 critical | 12.1% | 2018-12-05 |
| CVE-2017-18580 | The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode. | Patch early | 9.8 critical | 12.1% | 2019-08-22 |
| CVE-2023-42115 | Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in… | Patch early | 9.8 critical | 12.1% | 2024-05-03 |
| CVE-2020-36911 | Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges… | Patch early | 9.8 critical | 12.1% | 2026-01-13 |
| CVE-2024-8529 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/a… | Patch early | 10.0 critical | 12.1% | 2024-09-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt