CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,921 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-02
36,693 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-15605 | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed | Patch early | 9.8 critical | 57.1% | 2020-02-07 |
| CVE-2022-48323 | Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated at… | Patch early | 9.8 critical | 56.8% | 2023-02-13 |
| CVE-2017-9788 | In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or… | Patch early | 9.1 critical | 56.8% | 2017-07-13 |
| CVE-2020-28018 | Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL. | Patch early | 9.8 critical | 56.8% | 2021-05-06 |
| CVE-2018-9161 | Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account by reading… | Patch early | 9.8 critical | 56.7% | 2018-03-31 |
| CVE-2021-24472 | The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users,… | Patch early | 9.8 critical | 56.6% | 2021-08-02 |
| CVE-2023-6989 | The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up… | Patch early | 9.8 critical | 56.6% | 2024-02-05 |
| CVE-2022-23881 | ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php. | Patch early | 9.8 critical | 56.5% | 2022-03-23 |
| CVE-2022-25237 | Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthori… | Patch early | 9.8 critical | 56.4% | 2022-06-02 |
| CVE-2024-34716 | PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread… | Patch early | 9.6 critical | 56.4% | 2024-05-14 |
| CVE-2019-17506 | There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the ro… | Patch early | 9.8 critical | 56.4% | 2019-10-11 |
| CVE-2025-1661 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi… | Patch early | 9.8 critical | 56.4% | 2025-03-11 |
| CVE-2022-23521 | Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. These attributes can be defined by a… | Patch early | 9.8 critical | 56.3% | 2023-01-17 |
| CVE-2022-22972 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A m… | Patch early | 9.8 critical | 56.3% | 2022-05-20 |
| CVE-2025-2945 | Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POST… | Patch early | 9.9 critical | 56.3% | 2025-04-03 |
| CVE-2024-53676 | A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution. | Patch early | 9.8 critical | 56.3% | 2024-11-27 |
| CVE-2022-25075 | TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows at… | Patch early | 9.8 critical | 56.2% | 2022-02-24 |
| CVE-2021-25003 | The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on th… | Patch early | 9.8 critical | 56.1% | 2022-03-14 |
| CVE-2018-14007 | Citrix XenServer 7.1 and newer allows Directory Traversal. | Patch early | 9.8 critical | 56.1% | 2018-08-15 |
| CVE-2021-33221 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints. | Patch early | 9.8 critical | 56.1% | 2021-07-07 |
| CVE-2023-32169 | D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentica… | Patch early | 9.8 critical | 56.1% | 2024-05-03 |
| CVE-2021-46442 | In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as d… | Patch early | 9.8 critical | 56.1% | 2022-04-27 |
| CVE-2025-49533 | Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbit… | Patch early | 9.8 critical | 56.1% | 2025-07-08 |
| CVE-2025-26319 | FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments. | Patch early | 9.8 critical | 55.9% | 2025-03-04 |
| CVE-2021-29200 | Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack | Patch early | 9.8 critical | 55.4% | 2021-04-27 |
| CVE-2021-45466 | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an auth… | Patch early | 9.8 critical | 55.3% | 2022-12-26 |
| CVE-2021-26747 | Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution. | Patch early | 9.8 critical | 54.8% | 2021-02-18 |
| CVE-2025-44148 | Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component | Patch early | 9.8 critical | 54.7% | 2025-06-03 |
| CVE-2021-21243 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted dat… | Patch early | 10.0 critical | 54.5% | 2021-01-15 |
| CVE-2019-0726 | A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows… | Patch early | 9.8 critical | 54.5% | 2019-04-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt