CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,033 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,701 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-13050 | A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_c… | Patch early | 9.8 critical | 39.8% | 2018-07-02 |
| CVE-2023-26258 | Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID t… | Patch early | 9.8 critical | 39.8% | 2023-07-03 |
| CVE-2021-32671 | Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when re… | Patch early | 10.0 critical | 39.7% | 2021-06-07 |
| CVE-2024-53944 | An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through M7628xUSAxUIv2… | Patch early | 9.8 critical | 39.7% | 2025-02-27 |
| CVE-2025-10230 | A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validatio… | Patch early | 10.0 critical | 39.7% | 2025-11-07 |
| CVE-2023-29374 | In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method. | Patch early | 9.8 critical | 39.7% | 2023-04-05 |
| CVE-2020-29390 | Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated a… | Patch early | 9.8 critical | 39.6% | 2020-11-30 |
| CVE-2019-12985 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). | Patch early | 9.8 critical | 39.5% | 2019-07-16 |
| CVE-2019-12986 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). | Patch early | 9.8 critical | 39.5% | 2019-07-16 |
| CVE-2017-3192 | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page… | Patch early | 9.8 critical | 39.5% | 2017-12-16 |
| CVE-2024-39943 | rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have… | Patch early | 9.9 critical | 39.5% | 2024-07-04 |
| CVE-2021-39275 | ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but th… | Patch early | 9.8 critical | 39.4% | 2021-09-16 |
| CVE-2022-0888 | The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found… | Patch early | 9.8 critical | 39.4% | 2022-03-23 |
| CVE-2020-10826 | /cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a r… | Patch early | 9.8 critical | 39.4% | 2020-03-26 |
| CVE-2024-28988 | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an… | Patch early | 9.8 critical | 39.4% | 2025-09-01 |
| CVE-2017-7679 | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type… | Patch early | 9.8 critical | 39.3% | 2017-06-20 |
| CVE-2019-12990 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal. | Patch early | 9.8 critical | 39.3% | 2019-07-16 |
| CVE-2017-18349 | parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code… | Patch early | 9.8 critical | 39.2% | 2018-10-23 |
| CVE-2019-16932 | A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data. | Patch early | 10.0 critical | 39.1% | 2019-09-30 |
| CVE-2022-46020 | WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. | Patch early | 9.8 critical | 39% | 2022-12-20 |
| CVE-2017-7504 | HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Ser… | Patch early | 9.8 critical | 38.9% | 2017-05-19 |
| CVE-2017-14463 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… | Patch early | 9.8 critical | 38.9% | 2018-04-05 |
| CVE-2020-21224 | A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control… | Patch early | 9.8 critical | 38.7% | 2021-02-22 |
| CVE-2019-16314 | Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2. | Patch early | 9.8 critical | 38.7% | 2019-09-14 |
| CVE-2025-20282 | A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affe… | Patch early | 10.0 critical | 38.7% | 2025-06-25 |
| CVE-2022-39396 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1… | Patch early | 9.8 critical | 38.7% | 2022-11-10 |
| CVE-2022-22916 | O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke. | Patch early | 9.8 critical | 38.7% | 2022-02-17 |
| CVE-2021-28476 | Windows Hyper-V Remote Code Execution Vulnerability | Patch early | 9.9 critical | 38.6% | 2021-05-11 |
| CVE-2022-4305 | The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which… | Patch early | 9.8 critical | 38.6% | 2023-01-23 |
| CVE-2023-49442 | Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request. | Patch early | 9.8 critical | 38.5% | 2024-01-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt