CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,038 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-42457 | Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh… | In your normal cycle | 9.1 critical | 3.1% | 2022-10-06 |
| CVE-2013-7088 | ClamAV before 0.97.7 has buffer overflow in the libclamav component | In your normal cycle | 9.8 critical | 3.1% | 2019-11-15 |
| CVE-2021-22795 | A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code… | In your normal cycle | 9.1 critical | 3.1% | 2022-04-13 |
| CVE-2021-36033 | Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Wi… | In your normal cycle | 9.1 critical | 3.1% | 2021-09-01 |
| CVE-2014-3622 | Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execu… | In your normal cycle | 9.8 critical | 3.1% | 2020-02-19 |
| CVE-2018-16983 | NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Con… | In your normal cycle | 9.8 critical | 3.1% | 2018-09-13 |
| CVE-2019-14300 | Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a denial of service or code execut… | In your normal cycle | 9.8 critical | 3.1% | 2019-08-26 |
| CVE-2019-14308 | Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code execution via… | In your normal cycle | 9.8 critical | 3.1% | 2019-08-26 |
| CVE-2023-39008 | A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23… | In your normal cycle | 9.8 critical | 3.1% | 2023-08-09 |
| CVE-2017-8399 | PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures.… | In your normal cycle | 9.8 critical | 3.1% | 2017-05-01 |
| CVE-2017-7637 | QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges. | In your normal cycle | 9.8 critical | 3.1% | 2018-06-05 |
| CVE-2015-7670 | Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordPress allow remote attackers to… | In your normal cycle | 9.8 critical | 3.1% | 2017-09-26 |
| CVE-2022-21165 | All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into… | In your normal cycle | 9.8 critical | 3.1% | 2022-08-29 |
| CVE-2024-44402 | D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm. | In your normal cycle | 9.8 critical | 3.1% | 2024-09-06 |
| CVE-2018-0318 | A vulnerability in the password reset function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain… | In your normal cycle | 9.8 critical | 3.1% | 2018-06-07 |
| CVE-2018-0319 | A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to g… | In your normal cycle | 9.8 critical | 3.1% | 2018-06-07 |
| CVE-2019-16722 | ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation. | In your normal cycle | 9.8 critical | 3.1% | 2019-09-23 |
| CVE-2020-28900 | Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges… | In your normal cycle | 9.8 critical | 3.1% | 2021-05-24 |
| CVE-2019-14281 | The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. | In your normal cycle | 9.8 critical | 3.1% | 2019-07-26 |
| CVE-2019-14282 | The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. | In your normal cycle | 9.8 critical | 3.1% | 2019-07-26 |
| CVE-2017-18187 | In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity(… | In your normal cycle | 9.8 critical | 3.1% | 2018-02-14 |
| CVE-2022-1996 | Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0. | In your normal cycle | 9.1 critical | 3.1% | 2022-06-08 |
| CVE-2017-18206 | In utils.c in zsh before 5.4, symlink expansion had a buffer overflow. | In your normal cycle | 9.8 critical | 3.1% | 2018-02-27 |
| CVE-2016-10131 | system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from fi… | In your normal cycle | 9.8 critical | 3.1% | 2017-01-12 |
| CVE-2024-32022 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_gui.py. This vulnerability is f… | In your normal cycle | 9.1 critical | 3.1% | 2024-04-16 |
| CVE-2022-46641 | D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSe… | In your normal cycle | 9.9 critical | 3.1% | 2022-12-23 |
| CVE-2022-46642 | D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo f… | In your normal cycle | 9.9 critical | 3.1% | 2022-12-23 |
| CVE-2022-48107 | D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerabili… | In your normal cycle | 9.8 critical | 3.1% | 2023-01-27 |
| CVE-2022-48108 | D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerabil… | In your normal cycle | 9.8 critical | 3.1% | 2023-01-27 |
| CVE-2019-13566 | An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. A buffer overflow allows att… | In your normal cycle | 9.8 critical | 3.1% | 2019-11-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt