CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,058 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,702 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-40871 | Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if s… | Patch early | 9.8 critical | 33.4% | 2022-10-12 |
| CVE-2025-6440 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary… | Patch early | 9.8 critical | 33.3% | 2025-10-24 |
| CVE-2026-1357 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up… | Patch early | 9.8 critical | 33.3% | 2026-02-11 |
| CVE-2021-20093 | A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to discl… | Patch early | 9.1 critical | 33.3% | 2021-06-16 |
| CVE-2026-21445 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langfl… | Patch early | 9.1 critical | 33.3% | 2026-01-02 |
| CVE-2021-46314 | A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bin… | Patch early | 9.8 critical | 33.3% | 2022-02-17 |
| CVE-2019-18889 | An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces c… | Patch early | 9.8 critical | 33.2% | 2019-11-21 |
| CVE-2016-1000027 | Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data.… | Patch early | 9.8 critical | 33.2% | 2020-01-02 |
| CVE-2023-33625 | D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxml… | Patch early | 9.8 critical | 33.2% | 2023-06-12 |
| CVE-2020-11710 | An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The ve… | Patch early | 9.8 critical | 33.1% | 2020-04-12 |
| CVE-2022-31680 | The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on… | Patch early | 9.1 critical | 33.1% | 2022-10-07 |
| CVE-2020-35713 | Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters t… | Patch early | 9.8 critical | 32.9% | 2020-12-26 |
| CVE-2018-1000517 | BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget… | Patch early | 9.8 critical | 32.9% | 2018-06-26 |
| CVE-2019-0697 | A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows… | Patch early | 9.8 critical | 32.9% | 2019-04-09 |
| CVE-2020-11546 | SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticate… | Patch early | 9.8 critical | 32.8% | 2020-07-14 |
| CVE-2022-29078 | The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionNa… | Patch early | 9.8 critical | 32.8% | 2022-04-25 |
| CVE-2024-29276 | An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerContr… | Patch early | 9.8 critical | 32.8% | 2024-04-02 |
| CVE-2016-7456 | VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attack… | Patch early | 9.8 critical | 32.8% | 2016-12-29 |
| CVE-2021-40531 | Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quara… | Patch early | 9.8 critical | 32.8% | 2021-09-06 |
| CVE-2018-7114 | HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to remote buffer overflow in dbman leading to code execution. T… | Patch early | 9.8 critical | 32.8% | 2018-12-03 |
| CVE-2017-5334 | Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have… | Patch early | 9.8 critical | 32.8% | 2017-03-24 |
| CVE-2024-10124 | The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and ac… | Patch early | 9.8 critical | 32.7% | 2024-12-12 |
| CVE-2018-16144 | The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command injection du… | Patch early | 9.8 critical | 32.7% | 2018-09-05 |
| CVE-2025-47981 | Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network. | Patch early | 9.8 critical | 32.7% | 2025-07-08 |
| CVE-2022-2564 | Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6. | Patch early | 9.8 critical | 32.7% | 2022-07-28 |
| CVE-2022-24108 | The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentia… | Patch early | 9.8 critical | 32.6% | 2022-05-17 |
| CVE-2024-1874 | In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient es… | Patch early | 9.4 critical | 32.6% | 2024-04-29 |
| CVE-2023-33735 | D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNA… | Patch early | 9.8 critical | 32.6% | 2023-05-31 |
| CVE-2022-25077 | TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows… | Patch early | 9.8 critical | 32.6% | 2022-02-24 |
| CVE-2022-4116 | A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to… | Patch early | 9.8 critical | 32.5% | 2022-11-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt