CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,359 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,624 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-46574 | An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmware… | Patch early | 9.8 critical | 65.4% | 2023-10-25 |
| CVE-2020-36708 | The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello… | Patch early | 9.8 critical | 65.3% | 2023-06-07 |
| CVE-2025-25292 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-s… | Patch early | 9.8 critical | 65.1% | 2025-03-12 |
| CVE-2023-6329 | An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" opt… | Patch early | 9.8 critical | 65% | 2023-11-27 |
| CVE-2024-54676 | Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions a… | Patch early | 9.8 critical | 64.9% | 2025-01-08 |
| CVE-2018-8476 | A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deploymen… | Patch early | 9.8 critical | 64.8% | 2018-11-14 |
| CVE-2022-23221 | H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FOR… | Patch early | 9.8 critical | 64.8% | 2022-01-19 |
| CVE-2025-25256 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSI… | Patch early | 9.8 critical | 64.7% | 2025-08-12 |
| CVE-2021-22707 | A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking… | Patch early | 9.8 critical | 64.6% | 2021-07-21 |
| CVE-2022-31499 | Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists b… | Patch early | 9.8 critical | 64.6% | 2022-08-25 |
| CVE-2023-44350 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could… | Patch early | 9.8 critical | 64.6% | 2023-11-17 |
| CVE-2024-4883 | In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthe… | Patch early | 9.8 critical | 64.5% | 2024-06-25 |
| CVE-2023-41109 | SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection. | Patch early | 9.8 critical | 64.5% | 2023-08-28 |
| CVE-2022-29155 | In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL st… | Patch early | 9.8 critical | 64.5% | 2022-05-04 |
| CVE-2018-15727 | Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie… | Patch early | 9.8 critical | 64.3% | 2018-08-29 |
| CVE-2021-40865 | An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (R… | Patch early | 9.8 critical | 64.2% | 2021-10-25 |
| CVE-2023-39475 | Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulne… | Patch early | 9.8 critical | 64.1% | 2024-05-03 |
| CVE-2022-1609 | The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API h… | Patch early | 9.8 critical | 64.1% | 2024-01-16 |
| CVE-2020-8466 | A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled,… | Patch early | 9.8 critical | 64.1% | 2020-12-17 |
| CVE-2021-41081 | Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search. | Patch early | 9.8 critical | 64.1% | 2021-11-11 |
| CVE-2024-47407 | A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to i… | Patch early | 10.0 critical | 64% | 2024-11-22 |
| CVE-2023-5652 | The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it… | Patch early | 9.8 critical | 63.7% | 2023-11-20 |
| CVE-2024-37014 | Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a P… | Patch early | 9.8 critical | 63.7% | 2024-06-10 |
| CVE-2022-30547 | A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted… | Patch early | 9.9 critical | 63.7% | 2022-08-22 |
| CVE-2023-26475 | XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted… | Patch early | 9.9 critical | 63.6% | 2023-03-02 |
| CVE-2025-62168 | Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows inf… | Patch early | 10.0 critical | 63.4% | 2025-10-17 |
| CVE-2023-29017 | vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host obj… | Patch early | 10.0 critical | 63.2% | 2023-04-06 |
| CVE-2023-45878 | GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The en… | Patch early | 9.8 critical | 63.1% | 2023-11-14 |
| CVE-2023-51409 | Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot:… | Patch early | 10.0 critical | 63.1% | 2024-04-12 |
| CVE-2023-49606 | A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header… | Patch early | 9.8 critical | 63.1% | 2024-05-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt