CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,973 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,699 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-7102 | Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue… | Patch early | 9.8 critical | 44.6% | 2023-12-24 |
| CVE-1999-0043 | Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. | Patch early | 9.8 critical | 44.6% | 1996-12-04 |
| CVE-2022-24313 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remot… | Patch early | 9.8 critical | 44.6% | 2022-02-09 |
| CVE-2016-2177 | OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of se… | Patch early | 9.8 critical | 44.5% | 2016-06-20 |
| CVE-2024-56511 | DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.Tok… | Patch early | 9.8 critical | 44.5% | 2025-01-10 |
| CVE-2023-32564 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve… | Patch early | 9.8 critical | 44.4% | 2023-08-10 |
| CVE-2021-35042 | Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web applica… | Patch early | 9.8 critical | 44.4% | 2021-07-02 |
| CVE-2019-13635 | The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal. | Patch early | 9.1 critical | 44.4% | 2019-07-30 |
| CVE-2024-48307 | JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData. | Patch early | 9.8 critical | 44.3% | 2024-10-31 |
| CVE-2020-5505 | Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-ph… | Patch early | 9.8 critical | 44.3% | 2020-01-14 |
| CVE-2021-42887 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm. | Patch early | 9.8 critical | 44.3% | 2022-06-03 |
| CVE-2022-41903 | Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality i… | Patch early | 9.8 critical | 44.3% | 2023-01-17 |
| CVE-2016-2182 | The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to c… | Patch early | 9.8 critical | 44.2% | 2016-09-16 |
| CVE-2024-55556 | A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server b… | Patch early | 9.8 critical | 44.1% | 2025-01-07 |
| CVE-2020-5514 | Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI. | Patch early | 9.1 critical | 44.1% | 2020-01-06 |
| CVE-2019-7839 | ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploita… | Patch early | 9.8 critical | 44.1% | 2019-06-12 |
| CVE-2017-17733 | Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request. | Patch early | 9.8 critical | 44.1% | 2017-12-18 |
| CVE-2023-2227 | Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0. | Patch early | 9.1 critical | 44% | 2023-04-21 |
| CVE-2024-26304 | There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sendin… | Patch early | 9.8 critical | 44% | 2024-05-01 |
| CVE-2019-12583 | Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts… | Patch early | 9.1 critical | 43.9% | 2019-06-27 |
| CVE-2022-0479 | The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL stateme… | Patch early | 9.8 critical | 43.8% | 2022-03-28 |
| CVE-2025-30065 | Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recom… | Patch early | 9.8 critical | 43.6% | 2025-04-01 |
| CVE-2024-8672 | The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,… | Patch early | 9.9 critical | 43.6% | 2024-11-28 |
| CVE-2024-7591 | Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * EC… | Patch early | 10.0 critical | 43.5% | 2024-09-05 |
| CVE-2021-25833 | A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an… | Patch early | 9.8 critical | 43.5% | 2021-03-01 |
| CVE-2025-61622 | Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows… | Patch early | 9.8 critical | 43.5% | 2025-10-01 |
| CVE-2024-3080 | Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device. | Patch early | 9.8 critical | 43.5% | 2024-06-14 |
| CVE-2019-14314 | A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability… | Patch early | 9.8 critical | 43.4% | 2019-08-27 |
| CVE-2022-0773 | The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then exe… | Patch early | 9.8 critical | 43.3% | 2022-05-02 |
| CVE-2023-35042 | GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData with… | Patch early | 9.8 critical | 43.2% | 2023-06-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt