CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-2894 | An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT S… | Patch early | 9.8 critical | 31% | 2017-11-07 |
| CVE-2023-25279 | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload. | Patch early | 9.8 critical | 31% | 2023-03-13 |
| CVE-2019-20933 | InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may hav… | Patch early | 9.8 critical | 30.9% | 2020-11-19 |
| CVE-2025-34036 | An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that… | Patch early | 9.8 critical | 30.9% | 2025-06-24 |
| CVE-2023-36210 | MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword paramete… | Patch early | 9.8 critical | 30.9% | 2023-08-01 |
| CVE-2017-1000002 | ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code ex… | Patch early | 9.8 critical | 30.8% | 2017-07-17 |
| CVE-2020-29045 | The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on th… | Patch early | 9.8 critical | 30.8% | 2021-03-11 |
| CVE-2024-56064 | Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Serv… | Patch early | 10.0 critical | 30.8% | 2024-12-31 |
| CVE-2022-1812 | Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10. | Patch early | 9.8 critical | 30.8% | 2023-01-14 |
| CVE-2020-11975 | Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code wit… | Patch early | 9.8 critical | 30.6% | 2020-06-05 |
| CVE-2017-12561 | A remote code execution vulnerability in HPE intelligent Management Center (iMC) PLAT version Plat 7.3 E0504P4 and earlier was found. | Patch early | 9.8 critical | 30.6% | 2018-02-15 |
| CVE-2023-6016 | An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature. | Patch early | 9.8 critical | 30.6% | 2023-11-16 |
| CVE-2021-21892 | A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A spe… | Patch early | 9.9 critical | 30.4% | 2021-12-22 |
| CVE-2018-8828 | A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially crafted REGISTER message with… | Patch early | 9.8 critical | 30.4% | 2018-03-20 |
| CVE-2020-14825 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0… | Patch early | 9.8 critical | 30.4% | 2020-10-21 |
| CVE-2022-26265 | Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter. | Patch early | 9.8 critical | 30.4% | 2022-03-18 |
| CVE-2019-1867 | A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on… | Patch early | 10.0 critical | 30.3% | 2019-05-10 |
| CVE-2024-41874 | ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code… | Patch early | 9.8 critical | 30.3% | 2024-09-13 |
| CVE-2018-18472 | Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1… | Patch early | 9.8 critical | 30.3% | 2019-06-19 |
| CVE-2011-4373 | Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of se… | Patch early | 9.8 critical | 30.3% | 2012-01-10 |
| CVE-2019-5128 | A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthent… | Patch early | 9.8 critical | 30.2% | 2019-10-25 |
| CVE-2022-40881 | SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php | Patch early | 9.8 critical | 30.1% | 2022-11-17 |
| CVE-2023-37754 | PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail. | Patch early | 9.8 critical | 30% | 2023-07-28 |
| CVE-2024-12847 | NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary… | Patch early | 9.8 critical | 29.9% | 2025-01-10 |
| CVE-2018-12571 | uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for… | Patch early | 9.8 critical | 29.9% | 2018-07-05 |
| CVE-2021-21477 | SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacke… | Patch early | 9.9 critical | 29.8% | 2021-02-09 |
| CVE-2017-8947 | A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found. | Patch early | 9.8 critical | 29.8% | 2018-02-15 |
| CVE-2023-4474 | The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V… | Patch early | 9.8 critical | 29.7% | 2023-11-30 |
| CVE-2023-52442 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in compound request `smb2_get_msg()` in s… | Patch early | 9.1 critical | 29.6% | 2024-02-21 |
| CVE-2018-17888 | NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session I… | Patch early | 9.8 critical | 29.6% | 2018-10-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt