CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,267 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,711 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-37642 | TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCh… | Patch early | 9.1 critical | 11.4% | 2024-06-14 |
| CVE-2022-35559 | A stack overflow vulnerability exists in /goform/setAutoPing in Tenda W6 V1.0.0.9(4122), which allows an attacker to construct ping1 parameters and pi… | Patch early | 9.8 critical | 11.4% | 2022-08-12 |
| CVE-2021-26432 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | Patch early | 9.8 critical | 11.3% | 2021-08-12 |
| CVE-2023-46220 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | Patch early | 9.8 critical | 11.3% | 2023-12-19 |
| CVE-2023-46225 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | Patch early | 9.8 critical | 11.3% | 2023-12-19 |
| CVE-2023-46257 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | Patch early | 9.8 critical | 11.3% | 2023-12-19 |
| CVE-2023-46259 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | Patch early | 9.8 critical | 11.3% | 2023-12-19 |
| CVE-2023-46261 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | Patch early | 9.8 critical | 11.3% | 2023-12-19 |
| CVE-2019-13462 | Lansweeper before 7.1.117.4 allows unauthenticated SQL injection. | Patch early | 9.1 critical | 11.3% | 2019-08-12 |
| CVE-2025-13184 | Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9… | Patch early | 9.8 critical | 11.3% | 2025-12-10 |
| CVE-2017-0372 | Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities. | Patch early | 9.8 critical | 11.3% | 2018-04-13 |
| CVE-2022-35698 | Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of th… | Patch early | 10.0 critical | 11.3% | 2022-10-14 |
| CVE-2026-33478 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain togeth… | Patch early | 10.0 critical | 11.2% | 2026-03-23 |
| CVE-2022-20780 | Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM)… | Patch early | 9.9 critical | 11.2% | 2022-05-04 |
| CVE-2022-25759 | The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload. | Patch early | 9.9 critical | 11.2% | 2022-07-22 |
| CVE-2024-33699 | The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator pas… | Patch early | 9.9 critical | 11.2% | 2024-10-30 |
| CVE-2018-12813 | Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution. | Patch early | 9.8 critical | 11.2% | 2018-10-17 |
| CVE-2018-12814 | Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution. | Patch early | 9.8 critical | 11.2% | 2018-10-17 |
| CVE-2004-0005 | Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding… | Patch early | 9.8 critical | 11.2% | 2004-03-03 |
| CVE-2017-8817 | The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application c… | Patch early | 9.8 critical | 11.2% | 2017-11-29 |
| CVE-2023-23489 | The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' para… | Patch early | 9.8 critical | 11.2% | 2023-01-20 |
| CVE-2001-0248 | Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT comman… | Patch early | 9.8 critical | 11.2% | 2001-06-18 |
| CVE-2020-8298 | fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeS… | Patch early | 9.8 critical | 11.2% | 2021-03-04 |
| CVE-2025-52376 | An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, al… | Patch early | 9.8 critical | 11.2% | 2025-07-15 |
| CVE-2026-22778 | vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimo… | Patch early | 9.8 critical | 11.2% | 2026-02-02 |
| CVE-2018-5353 | The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privilege… | Patch early | 9.8 critical | 11.1% | 2020-09-30 |
| CVE-2019-17638 | In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 4… | Patch early | 9.4 critical | 11.1% | 2020-07-09 |
| CVE-2016-10107 | Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header. | Patch early | 9.8 critical | 11.1% | 2017-01-03 |
| CVE-2021-41560 | OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php. | Patch early | 9.8 critical | 11.1% | 2021-12-15 |
| CVE-2019-17195 | Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potentia… | Patch early | 9.8 critical | 11.1% | 2019-10-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt