CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-1600 | A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attacke… | Patch early | 9.3 critical | 32.5% | 2024-04-10 |
| CVE-2016-0799 | The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows… | Patch early | 9.8 critical | 32.4% | 2016-03-03 |
| CVE-2023-30194 | Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). | Patch early | 9.8 critical | 32.4% | 2023-05-10 |
| CVE-2026-0769 | Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… | Patch early | 9.8 critical | 32.3% | 2026-01-23 |
| CVE-2019-18394 | A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary… | Patch early | 9.8 critical | 32.3% | 2019-10-24 |
| CVE-2025-13315 | Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authenticatio… | Patch early | 9.8 critical | 32.3% | 2025-11-19 |
| CVE-2024-24996 | A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arb… | Patch early | 9.8 critical | 32.2% | 2024-04-19 |
| CVE-2024-57045 | A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication.… | Patch early | 9.8 critical | 32.2% | 2025-02-18 |
| CVE-2022-0651 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter… | Patch early | 9.8 critical | 32.2% | 2022-02-24 |
| CVE-2020-10549 | rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext,… | Patch early | 9.8 critical | 32.1% | 2020-06-04 |
| CVE-2020-7357 | Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and e… | Patch early | 9.6 critical | 32.1% | 2020-08-06 |
| CVE-2019-13086 | core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting… | Patch early | 9.8 critical | 32% | 2019-06-30 |
| CVE-2016-6303 | Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (o… | Patch early | 9.8 critical | 32% | 2016-09-16 |
| CVE-2018-7836 | An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow uploa… | Patch early | 9.8 critical | 32% | 2018-12-24 |
| CVE-2022-35620 | D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function binary.soapcgi_main. | Patch early | 9.8 critical | 31.9% | 2022-08-03 |
| CVE-2022-28054 | Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted… | Patch early | 9.8 critical | 31.9% | 2022-05-02 |
| CVE-2022-24989 | TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object… | Patch early | 9.8 critical | 31.9% | 2023-08-20 |
| CVE-2025-68926 | RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardco… | Patch early | 9.8 critical | 31.9% | 2025-12-30 |
| CVE-2024-50379 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file system… | Patch early | 9.8 critical | 31.8% | 2024-12-17 |
| CVE-2023-30261 | Command Injection vulnerability in OpenWB 1.6 and 1.7 allows remote attackers to run arbitrary commands via crafted GET request. | Patch early | 9.8 critical | 31.7% | 2023-06-26 |
| CVE-2019-15859 | Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the… | Patch early | 9.8 critical | 31.5% | 2019-10-09 |
| CVE-2022-45092 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Man… | Patch early | 9.9 critical | 31.4% | 2023-01-10 |
| CVE-2023-26613 | An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system… | Patch early | 9.8 critical | 31.4% | 2023-06-29 |
| CVE-2024-5982 | A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in… | Patch early | 9.8 critical | 31.3% | 2024-10-29 |
| CVE-2009-2512 | The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD… | Patch early | 9.8 critical | 31.2% | 2009-11-11 |
| CVE-2025-29085 | SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCou… | Patch early | 9.8 critical | 31.2% | 2025-04-02 |
| CVE-2018-18925 | Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the fil… | Patch early | 9.8 critical | 31.1% | 2018-11-04 |
| CVE-2023-51126 | Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOTE… | Patch early | 9.8 critical | 31.1% | 2024-01-10 |
| CVE-2017-2894 | An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT S… | Patch early | 9.8 critical | 31% | 2017-11-07 |
| CVE-2023-25279 | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload. | Patch early | 9.8 critical | 31% | 2023-03-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt