CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-7846 | A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Qu… | Patch early | 9.8 critical | 29.6% | 2019-05-22 |
| CVE-2019-19825 | On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin… | Patch early | 9.8 critical | 29.6% | 2020-01-27 |
| CVE-2019-19492 | FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml. | Patch early | 9.8 critical | 29.4% | 2019-12-02 |
| CVE-2024-4548 | An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is sp… | Patch early | 9.8 critical | 29.4% | 2024-05-06 |
| CVE-2012-1891 | Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote atta… | Patch early | 9.8 critical | 29.4% | 2012-07-10 |
| CVE-2018-14699 | System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execu… | Patch early | 9.8 critical | 29.4% | 2018-12-03 |
| CVE-2020-9480 | In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a share… | Patch early | 9.8 critical | 29.4% | 2020-06-23 |
| CVE-2022-4101 | The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthentic… | Patch early | 9.1 critical | 29.4% | 2023-01-16 |
| CVE-2023-34800 | D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main. | Patch early | 9.8 critical | 29.3% | 2023-06-15 |
| CVE-2023-20032 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of C… | Patch early | 9.8 critical | 29.3% | 2023-03-01 |
| CVE-2018-14767 | In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault and… | Patch early | 9.8 critical | 29.3% | 2018-07-31 |
| CVE-2024-32002 | Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be cr… | Patch early | 9.0 critical | 29.2% | 2024-05-14 |
| CVE-2025-59719 | An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4… | Patch early | 9.8 critical | 29.2% | 2025-12-09 |
| CVE-2018-8273 | A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Se… | Patch early | 9.8 critical | 29.2% | 2018-08-15 |
| CVE-2020-12011 | A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution. This i… | Patch early | 9.8 critical | 29.2% | 2020-07-16 |
| CVE-2024-39907 | 1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, lea… | Patch early | 9.8 critical | 29.2% | 2024-07-18 |
| CVE-2022-25017 | Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field. | Patch early | 9.1 critical | 29.1% | 2022-04-01 |
| CVE-2018-8421 | A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulner… | Patch early | 9.8 critical | 29.1% | 2018-09-13 |
| CVE-2021-30176 | The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint. | Patch early | 9.8 critical | 29% | 2021-04-13 |
| CVE-2024-6366 | The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via… | Patch early | 9.1 critical | 29% | 2024-07-29 |
| CVE-2020-15568 | TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerabi… | Patch early | 9.8 critical | 29% | 2021-01-30 |
| CVE-2017-7577 | XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request. | Patch early | 9.8 critical | 29% | 2017-04-07 |
| CVE-2019-7107 | Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation could lead to arbitrary code execu… | Patch early | 9.8 critical | 28.9% | 2019-05-23 |
| CVE-2020-35613 | An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend… | Patch early | 9.8 critical | 28.9% | 2020-12-28 |
| CVE-2019-9848 | LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. L… | Patch early | 9.8 critical | 28.9% | 2019-07-17 |
| CVE-2023-34991 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 thro… | Patch early | 9.8 critical | 28.8% | 2023-11-14 |
| CVE-2025-1128 | The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file… | Patch early | 9.8 critical | 28.8% | 2025-02-25 |
| CVE-2022-47945 | ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). A… | Patch early | 9.8 critical | 28.7% | 2022-12-23 |
| CVE-2024-8353 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… | Patch early | 9.8 critical | 28.7% | 2024-09-28 |
| CVE-2015-8277 | Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote attackers to… | Patch early | 9.8 critical | 28.7% | 2016-02-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt