CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,045 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,701 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-24338 | An issue was discovered in picoTCP through 1.7.0. The DNS domain name record decompression functionality in pico_dns_decompress_name() in pico_dns_com… | Patch early | 9.8 critical | 37.2% | 2020-12-11 |
| CVE-2018-11143 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46). | Patch early | 9.8 critical | 37.2% | 2018-06-02 |
| CVE-2022-0739 | The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL… | Patch early | 9.8 critical | 37.2% | 2022-03-21 |
| CVE-2022-1905 | The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX a… | Patch early | 9.8 critical | 37.1% | 2022-06-20 |
| CVE-2022-27255 | In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker… | Patch early | 9.8 critical | 37.1% | 2022-08-01 |
| CVE-2024-4434 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, an… | Patch early | 9.8 critical | 36.9% | 2024-05-14 |
| CVE-2020-28017 | Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: re… | Patch early | 9.8 critical | 36.9% | 2021-05-06 |
| CVE-2020-11896 | The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling. | Patch early | 10.0 critical | 36.9% | 2020-06-17 |
| CVE-2021-22652 | Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to cha… | Patch early | 9.8 critical | 36.8% | 2021-02-11 |
| CVE-2021-3120 | An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve… | Patch early | 9.8 critical | 36.8% | 2021-02-22 |
| CVE-2022-35712 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could res… | Patch early | 9.8 critical | 36.8% | 2022-10-14 |
| CVE-2024-45622 | ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass. | Patch early | 9.8 critical | 36.7% | 2024-09-02 |
| CVE-2023-20126 | A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute… | Patch early | 9.8 critical | 36.7% | 2023-05-04 |
| CVE-2021-30461 | A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR va… | Patch early | 9.8 critical | 36.6% | 2021-05-29 |
| CVE-2021-47667 | An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to exec… | Patch early | 10.0 critical | 36.6% | 2025-04-05 |
| CVE-2024-51482 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Inj… | Patch early | 9.9 critical | 36.6% | 2024-10-31 |
| CVE-2017-8220 | TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by placi… | Patch early | 9.9 critical | 36.6% | 2017-04-25 |
| CVE-2020-10547 | rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stor… | Patch early | 9.8 critical | 36.6% | 2020-06-04 |
| CVE-2020-11981 | An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ)… | Patch early | 9.8 critical | 36.5% | 2020-07-17 |
| CVE-2019-17564 | Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in… | Patch early | 9.8 critical | 36.5% | 2020-04-01 |
| CVE-2020-10548 | rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext,… | Patch early | 9.8 critical | 36.5% | 2020-06-04 |
| CVE-2022-25064 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr. | Patch early | 9.8 critical | 36.5% | 2022-02-25 |
| CVE-2022-39428 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are af… | Patch early | 9.8 critical | 36.5% | 2022-10-18 |
| CVE-2021-22930 | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption,… | Patch early | 9.8 critical | 36.5% | 2021-10-07 |
| CVE-2019-8917 | SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes… | Patch early | 9.8 critical | 36.4% | 2019-02-18 |
| CVE-2021-25274 | The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queu… | Patch early | 9.8 critical | 36.4% | 2021-02-03 |
| CVE-2025-32814 | An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur. | Patch early | 9.8 critical | 36.4% | 2025-05-22 |
| CVE-2024-9932 | The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew… | Patch early | 9.8 critical | 36.4% | 2024-10-26 |
| CVE-2023-41727 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | Patch early | 9.8 critical | 36.4% | 2023-12-19 |
| CVE-2023-46216 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | Patch early | 9.8 critical | 36.4% | 2023-12-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt