CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,047 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,702 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-46217 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | Patch early | 9.8 critical | 36.4% | 2023-12-19 |
| CVE-2019-3932 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.… | Patch early | 9.8 critical | 36.3% | 2019-04-30 |
| CVE-2021-28481 | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch early | 9.8 critical | 36.2% | 2021-04-13 |
| CVE-2021-21881 | An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A spec… | Patch early | 9.9 critical | 36.2% | 2021-12-22 |
| CVE-2016-3141 | Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of… | Patch early | 9.8 critical | 36% | 2016-03-31 |
| CVE-2024-22476 | Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable esc… | Patch early | 10.0 critical | 36% | 2024-05-16 |
| CVE-2022-25236 | xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. | Patch early | 9.8 critical | 35.9% | 2022-02-16 |
| CVE-2022-23450 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Up… | Patch early | 9.8 critical | 35.7% | 2022-04-12 |
| CVE-2019-15846 | Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash. | Patch early | 9.8 critical | 35.7% | 2019-09-06 |
| CVE-2025-5306 | Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through… | Patch early | 9.8 critical | 35.7% | 2025-06-27 |
| CVE-2019-6339 | In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-… | Patch early | 9.8 critical | 35.6% | 2019-01-22 |
| CVE-2020-16152 | The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execut… | Patch early | 9.8 critical | 35.5% | 2021-11-14 |
| CVE-2024-6220 | The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages f… | Patch early | 9.8 critical | 35.5% | 2024-07-17 |
| CVE-2022-29337 | C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerabi… | Patch early | 9.8 critical | 35.5% | 2022-05-24 |
| CVE-2022-4606 | PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3. | Patch early | 9.8 critical | 35.4% | 2022-12-18 |
| CVE-2017-6639 | A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated… | Patch early | 9.8 critical | 35.4% | 2017-06-08 |
| CVE-2023-48023 | Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its docum… | Patch early | 9.1 critical | 35.3% | 2023-11-28 |
| CVE-2022-32417 | PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php. | Patch early | 9.8 critical | 35.2% | 2022-07-14 |
| CVE-2017-14462 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… | Patch early | 9.8 critical | 35.2% | 2018-04-05 |
| CVE-2017-14465 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… | Patch early | 9.8 critical | 35.2% | 2018-04-05 |
| CVE-2024-37084 | In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to wri… | Patch early | 9.8 critical | 35.2% | 2024-07-25 |
| CVE-2018-7842 | A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Prem… | Patch early | 9.8 critical | 35% | 2019-05-22 |
| CVE-2021-42756 | Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2… | Patch early | 9.8 critical | 35% | 2023-02-16 |
| CVE-2018-16158 | Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do n… | Patch early | 9.8 critical | 34.9% | 2018-08-30 |
| CVE-2023-32571 | Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods including Wh… | Patch early | 9.8 critical | 34.9% | 2023-06-22 |
| CVE-2021-43118 | A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafte… | Patch early | 9.8 critical | 34.8% | 2022-03-29 |
| CVE-2022-31446 | Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/gofo… | Patch early | 9.8 critical | 34.8% | 2022-06-14 |
| CVE-2022-32054 | Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter. | Patch early | 9.8 critical | 34.8% | 2022-07-07 |
| CVE-2024-10470 | The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insuffi… | Patch early | 9.8 critical | 34.8% | 2024-11-09 |
| CVE-2022-45025 | Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import f… | Patch early | 9.8 critical | 34.8% | 2022-12-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt