CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,014 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,699 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-38476 | Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend ap… | Patch early | 9.8 critical | 41.6% | 2024-07-01 |
| CVE-2018-19986 | In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR… | Patch early | 9.8 critical | 41.6% | 2019-05-13 |
| CVE-2016-7480 | The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows r… | Patch early | 9.8 critical | 41.6% | 2017-01-11 |
| CVE-2020-23584 | Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRE… | Patch early | 9.8 critical | 41.4% | 2022-11-23 |
| CVE-2023-4473 | A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0… | Patch early | 9.8 critical | 41.3% | 2023-11-30 |
| CVE-2025-52665 | A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that expose… | Patch early | 10.0 critical | 41.1% | 2025-10-31 |
| CVE-2022-46476 | D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function. | Patch early | 9.8 critical | 41.1% | 2023-01-19 |
| CVE-2015-3253 | The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause… | Patch early | 9.8 critical | 41% | 2015-08-13 |
| CVE-2024-46986 | Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the uplo… | Patch early | 9.9 critical | 41% | 2024-09-18 |
| CVE-2020-24913 | A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to… | Patch early | 9.8 critical | 40.9% | 2021-03-04 |
| CVE-2023-4521 | The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor… | Patch early | 9.8 critical | 40.8% | 2023-09-25 |
| CVE-2016-10329 | Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell m… | Patch early | 9.8 critical | 40.8% | 2017-05-12 |
| CVE-2019-18939 | eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers w… | Patch early | 9.8 critical | 40.8% | 2019-11-14 |
| CVE-2023-43654 | TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling th… | Patch early | 10.0 critical | 40.7% | 2023-09-28 |
| CVE-2025-27520 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerability… | Patch early | 9.8 critical | 40.6% | 2025-04-04 |
| CVE-2024-38289 | A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote att… | Patch early | 9.8 critical | 40.6% | 2024-07-25 |
| CVE-2023-1730 | The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthen… | Patch early | 9.8 critical | 40.6% | 2023-05-02 |
| CVE-2026-2329 | An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage t… | Patch early | 9.8 critical | 40.6% | 2026-02-18 |
| CVE-2023-2564 | OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0. | Patch early | 10.0 critical | 40.5% | 2023-05-07 |
| CVE-2024-1601 | An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, allowing an attacker to delete a… | Patch early | 9.8 critical | 40.4% | 2024-04-16 |
| CVE-2025-52694 | Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vul… | Patch early | 10.0 critical | 40.4% | 2026-01-12 |
| CVE-2024-1800 | In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deseriali… | Patch early | 9.9 critical | 40.4% | 2024-03-20 |
| CVE-2019-18370 | An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application use… | Patch early | 9.8 critical | 40.3% | 2019-10-23 |
| CVE-2024-50330 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated att… | Patch early | 9.8 critical | 40.3% | 2024-11-12 |
| CVE-2022-25060 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing. | Patch early | 9.8 critical | 40.2% | 2022-02-25 |
| CVE-2023-36460 | Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, a… | Patch early | 9.9 critical | 40.1% | 2023-07-06 |
| CVE-2021-26709 | D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to take over… | Patch early | 9.8 critical | 40.1% | 2021-04-07 |
| CVE-2022-25369 | An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a lo… | Patch early | 9.8 critical | 40% | 2026-01-23 |
| CVE-2023-35138 | A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmw… | Patch early | 9.8 critical | 40% | 2023-11-30 |
| CVE-2024-10081 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs w… | Patch early | 10.0 critical | 39.9% | 2024-11-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt