CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,317 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,711 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-28561 | There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker… | Patch early | 9.8 critical | 10.1% | 2022-05-03 |
| CVE-2025-53833 | LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Ser… | Patch early | 10.0 critical | 10.1% | 2025-07-14 |
| CVE-2023-29468 | The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_EXT_1_IE_ID or XCC_EXT_2_IE_ID… | Patch early | 9.8 critical | 10.1% | 2023-08-14 |
| CVE-2020-12133 | The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java de… | Patch early | 9.8 critical | 10.1% | 2020-04-27 |
| CVE-2021-21479 | In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the syst… | Patch early | 9.1 critical | 10.1% | 2021-02-09 |
| CVE-2021-35336 | Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could… | Patch early | 9.8 critical | 10.1% | 2021-07-01 |
| CVE-2020-10541 | Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed i… | Patch early | 9.8 critical | 10.1% | 2020-03-13 |
| CVE-2020-22208 | SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php. | Patch early | 9.8 critical | 10.1% | 2021-06-16 |
| CVE-2018-7282 | The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi. | Patch early | 9.8 critical | 10.1% | 2019-12-06 |
| CVE-2020-0872 | A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from thi… | Patch early | 9.6 critical | 10.1% | 2020-03-12 |
| CVE-2022-0784 | The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex… | Patch early | 9.8 critical | 10.1% | 2022-03-28 |
| CVE-2016-5080 | Integer overflow in the rtxMemHeapAlloc function in asn1rt_a.lib in Objective Systems ASN1C for C/C++ before 7.0.2 allows context-dependent attackers… | Patch early | 9.8 critical | 10.1% | 2016-07-19 |
| CVE-2020-27265 | KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Roc… | Patch early | 9.8 critical | 10.1% | 2021-01-14 |
| CVE-2019-9020 | An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_dec… | Patch early | 9.8 critical | 10.1% | 2019-02-22 |
| CVE-2019-9021 | An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR re… | Patch early | 9.8 critical | 10.1% | 2019-02-22 |
| CVE-2020-5260 | Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git use… | Patch early | 9.3 critical | 10% | 2020-04-14 |
| CVE-2025-57772 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JDBC RCE bypass in DataEase. If… | Patch early | 9.8 critical | 10% | 2025-08-25 |
| CVE-2020-27481 | An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which… | Patch early | 9.8 critical | 10% | 2020-11-12 |
| CVE-2012-6706 | A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other prod… | Patch early | 9.8 critical | 10% | 2017-06-22 |
| CVE-2026-15733 | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attacke… | Patch early | 9.8 critical | 10% | 2026-08-06 |
| CVE-2016-9555 | The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows re… | Patch early | 9.8 critical | 10% | 2016-11-28 |
| CVE-2016-4121 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.6… | Patch early | 9.8 critical | 10% | 2016-06-16 |
| CVE-2020-17531 | A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoki… | In your normal cycle | 9.8 critical | 10% | 2020-12-08 |
| CVE-2019-10952 | An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based… | In your normal cycle | 9.8 critical | 10% | 2019-05-01 |
| CVE-2024-50387 | A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote a… | In your normal cycle | 9.8 critical | 10% | 2024-12-06 |
| CVE-2026-19681 | An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by… | In your normal cycle | 9.9 critical | 9.9% | 2026-08-14 |
| CVE-2017-5611 | SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL c… | In your normal cycle | 9.8 critical | 9.9% | 2017-01-30 |
| CVE-2020-11986 | To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build… | In your normal cycle | 9.8 critical | 9.9% | 2020-09-09 |
| CVE-2017-2750 | Insufficient Solution DLL Signature Validation allows potential execution of arbitrary code in HP LaserJet Enterprise printers, HP PageWide Enterprise… | In your normal cycle | 9.8 critical | 9.9% | 2018-01-23 |
| CVE-2021-40960 | Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow. | In your normal cycle | 9.8 critical | 9.9% | 2021-10-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt