CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,941 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-02
36,697 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-34718 | Windows TCP/IP Remote Code Execution Vulnerability | Patch early | 9.8 critical | 54.4% | 2022-09-13 |
| CVE-2019-17382 | An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the… | Patch early | 9.1 critical | 54.2% | 2019-10-09 |
| CVE-2022-38130 | The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path… | Patch early | 9.8 critical | 54.1% | 2022-08-10 |
| CVE-2018-1143 | A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to twon… | Patch early | 9.8 critical | 54% | 2018-04-19 |
| CVE-2024-23917 | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible | Patch early | 9.8 critical | 54% | 2024-02-06 |
| CVE-2019-9733 | An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an… | Patch early | 9.8 critical | 53.9% | 2019-04-11 |
| CVE-2021-27651 | In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication check… | Patch early | 9.8 critical | 53.8% | 2021-04-29 |
| CVE-2022-25487 | Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php. | Patch early | 9.8 critical | 53.8% | 2022-03-15 |
| CVE-2023-32645 | A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network requ… | Patch early | 9.8 critical | 53.8% | 2023-10-11 |
| CVE-2020-25107 | An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. There is no check on whether a domain name has '\0' termination. This may… | Patch early | 9.8 critical | 53.7% | 2020-12-11 |
| CVE-2020-25108 | An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The DNS response data length is not checked (it can be set to an arbitrar… | Patch early | 9.8 critical | 53.7% | 2020-12-11 |
| CVE-2020-25109 | An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The number of DNS queries/responses (set in a DNS header) is not checked… | Patch early | 9.8 critical | 53.7% | 2020-12-11 |
| CVE-2020-25110 | An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The length byte of a domain name in a DNS query/response is not checked,… | Patch early | 9.8 critical | 53.7% | 2020-12-11 |
| CVE-2016-2842 | The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocati… | Patch early | 9.8 critical | 53.7% | 2016-03-03 |
| CVE-2024-9441 | The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can… | Patch early | 9.8 critical | 53.5% | 2024-10-02 |
| CVE-2022-0513 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter… | Patch early | 9.8 critical | 53.5% | 2022-02-16 |
| CVE-2022-26148 | An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source cod… | Patch early | 9.8 critical | 53.4% | 2022-03-21 |
| CVE-2023-50231 | NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. This vulnerability allows remote atta… | Patch early | 9.6 critical | 53.3% | 2024-05-03 |
| CVE-2024-37843 | Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint. | Patch early | 9.8 critical | 53.2% | 2024-06-25 |
| CVE-2025-12420 | A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform th… | Patch early | 9.8 critical | 53.2% | 2026-01-12 |
| CVE-2026-10523 | An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated att… | Patch early | 9.9 critical | 53.1% | 2026-06-09 |
| CVE-2024-6396 | A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfi… | Patch early | 9.8 critical | 53.1% | 2024-07-12 |
| CVE-2019-11577 | dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses. | Patch early | 9.8 critical | 53.1% | 2019-04-28 |
| CVE-2024-32964 | Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat h… | Patch early | 9.0 critical | 53% | 2024-05-14 |
| CVE-2024-32238 | H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system pa… | Patch early | 9.8 critical | 52.9% | 2024-04-22 |
| CVE-2021-22160 | If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the… | Patch early | 9.8 critical | 52.9% | 2021-05-26 |
| CVE-2024-3922 | The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insuffi… | Patch early | 10.0 critical | 52.9% | 2024-06-13 |
| CVE-2024-29847 | Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated atta… | Patch early | 9.8 critical | 52.9% | 2024-09-12 |
| CVE-2024-50498 | Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This iss… | Patch early | 10.0 critical | 52.9% | 2024-10-28 |
| CVE-2020-29279 | PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remo… | Patch early | 9.8 critical | 52.9% | 2020-12-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt