CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,458 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,648 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-17207 | An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an att… | Patch early | 9.8 critical | 60.1% | 2018-09-19 |
| CVE-2020-3495 | A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to impro… | Patch early | 9.9 critical | 59.9% | 2020-09-04 |
| CVE-2023-0587 | A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent… | Patch early | 9.1 critical | 59.6% | 2023-02-01 |
| CVE-2024-10525 | In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libm… | Patch early | 9.8 critical | 59.5% | 2024-10-30 |
| CVE-2021-42342 | An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being… | Patch early | 9.8 critical | 59.5% | 2021-10-14 |
| CVE-2022-2143 | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code. | Patch early | 9.8 critical | 59.4% | 2022-07-22 |
| CVE-2020-24336 | An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c doesn't ver… | Patch early | 9.8 critical | 59.1% | 2020-12-11 |
| CVE-2020-13381 | openSIS through 7.4 allows SQL Injection. | Patch early | 9.8 critical | 59% | 2020-07-01 |
| CVE-2018-11218 | Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 becaus… | Patch early | 9.8 critical | 59% | 2018-06-17 |
| CVE-2019-17270 | Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?c… | Patch early | 9.8 critical | 58.9% | 2019-12-10 |
| CVE-2023-27034 | PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability. | Patch early | 9.8 critical | 58.7% | 2023-03-23 |
| CVE-2022-25061 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute. | Patch early | 9.8 critical | 58.7% | 2022-02-25 |
| CVE-2023-3224 | Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3. | Patch early | 9.8 critical | 58.6% | 2023-06-13 |
| CVE-2021-44152 | An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticat… | Patch early | 9.8 critical | 58.6% | 2021-12-13 |
| CVE-2022-24422 | Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker… | Patch early | 9.6 critical | 58.5% | 2022-05-26 |
| CVE-2002-0391 | Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, al… | Patch early | 9.8 critical | 58.1% | 2002-08-12 |
| CVE-2022-32174 | In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover. | Patch early | 9.0 critical | 58% | 2022-10-11 |
| CVE-2021-34427 | In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT vi… | Patch early | 9.8 critical | 58% | 2021-06-25 |
| CVE-2021-43267 | An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allo… | Patch early | 9.8 critical | 57.9% | 2021-11-02 |
| CVE-2020-25592 | In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH. | Patch early | 9.8 critical | 57.7% | 2020-11-06 |
| CVE-2025-48828 | Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting te… | Patch early | 9.0 critical | 57.6% | 2025-05-27 |
| CVE-2022-29517 | A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-craft… | Patch early | 9.9 critical | 57.6% | 2022-12-15 |
| CVE-2019-12815 | An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentic… | Patch early | 9.8 critical | 57.6% | 2019-07-19 |
| CVE-2021-44521 | When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enabl… | Patch early | 9.1 critical | 57.5% | 2022-02-11 |
| CVE-2022-25046 | A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request. | Patch early | 9.8 critical | 57.4% | 2022-07-07 |
| CVE-2018-1275 | Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over… | Patch early | 9.8 critical | 57.4% | 2018-04-11 |
| CVE-2017-16597 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1… | Patch early | 9.8 critical | 57.3% | 2018-01-23 |
| CVE-2019-15605 | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed | Patch early | 9.8 critical | 57.1% | 2020-02-07 |
| CVE-2022-48323 | Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated at… | Patch early | 9.8 critical | 56.8% | 2023-02-13 |
| CVE-2017-9788 | In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or… | Patch early | 9.1 critical | 56.8% | 2017-07-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt