CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,959 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,699 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-17181 | A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET or HEAD request that can result… | Patch early | 9.8 critical | 48.7% | 2019-10-28 |
| CVE-2022-29383 | NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-b… | Patch early | 9.8 critical | 48.5% | 2022-05-13 |
| CVE-2017-7581 | SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL… | Patch early | 9.8 critical | 48.4% | 2017-04-07 |
| CVE-2024-1520 | An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation… | Patch early | 9.8 critical | 48.2% | 2024-04-10 |
| CVE-2018-0258 | A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to an… | Patch early | 9.8 critical | 48.2% | 2018-05-02 |
| CVE-2023-51595 | Voltronic Power ViewPower Pro selectDeviceListBy SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec… | Patch early | 9.8 critical | 48.2% | 2024-05-03 |
| CVE-2017-17420 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is… | Patch early | 9.8 critical | 48.2% | 2018-02-08 |
| CVE-2022-33318 | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Soluti… | Patch early | 9.8 critical | 48.1% | 2022-07-20 |
| CVE-2024-39363 | A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505. A specia… | Patch early | 9.6 critical | 48.1% | 2025-01-14 |
| CVE-2024-34144 | A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers… | Patch early | 9.8 critical | 48.1% | 2024-05-02 |
| CVE-2018-20841 | HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the m… | Patch early | 9.8 critical | 47.9% | 2019-06-11 |
| CVE-2023-6018 | An attacker can overwrite any file on the server hosting MLflow without any authentication. | Patch early | 9.8 critical | 47.9% | 2023-11-16 |
| CVE-2022-36067 | vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass… | Patch early | 10.0 critical | 47.9% | 2022-09-06 |
| CVE-2020-10914 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not re… | Patch early | 9.8 critical | 47.9% | 2020-04-22 |
| CVE-2022-0679 | The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require… | Patch early | 9.8 critical | 47.8% | 2022-03-28 |
| CVE-2023-50919 | An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects… | Patch early | 9.8 critical | 47.8% | 2024-01-12 |
| CVE-2025-6216 | Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authenticati… | Patch early | 9.8 critical | 47.8% | 2025-06-21 |
| CVE-2019-14234 | An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, k… | Patch early | 9.8 critical | 47.7% | 2019-08-09 |
| CVE-2024-25065 | Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue. | Patch early | 9.1 critical | 47.7% | 2024-02-29 |
| CVE-2024-23759 | Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddA… | Patch early | 9.8 critical | 47.5% | 2024-02-12 |
| CVE-2023-43187 | A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execut… | Patch early | 9.8 critical | 47.4% | 2023-09-27 |
| CVE-2021-24370 | The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code executio… | Patch early | 9.8 critical | 47.4% | 2021-06-21 |
| CVE-2010-2965 | The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.… | Patch early | 9.8 critical | 47.4% | 2010-08-05 |
| CVE-2022-46164 | NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially cra… | Patch early | 9.4 critical | 47.4% | 2022-12-05 |
| CVE-2023-34598 | Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation f… | Patch early | 9.8 critical | 47.2% | 2023-06-29 |
| CVE-2023-47211 | A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lea… | Patch early | 9.1 critical | 47% | 2024-01-08 |
| CVE-2025-64095 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor… | Patch early | 10.0 critical | 47% | 2025-10-28 |
| CVE-2020-12029 | All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be… | Patch early | 9.0 critical | 47% | 2020-07-20 |
| CVE-2024-30568 | Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter. | Patch early | 9.8 critical | 46.9% | 2024-04-03 |
| CVE-2020-14645 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0… | Patch early | 9.8 critical | 46.9% | 2020-07-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt