CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-21690 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Patch early | 9.8 critical | 27.5% | 2023-02-14 |
| CVE-2023-36177 | An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafte… | Patch early | 9.8 critical | 27.5% | 2024-01-23 |
| CVE-2017-8686 | The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHC… | Patch early | 9.8 critical | 27.5% | 2017-09-13 |
| CVE-2025-20188 | A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco… | Patch early | 10.0 critical | 27.5% | 2025-05-07 |
| CVE-2025-32011 | KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get acce… | Patch early | 9.8 critical | 27.5% | 2025-05-01 |
| CVE-2018-14714 | System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system commands via the "load_script" U… | Patch early | 9.8 critical | 27.4% | 2019-05-13 |
| CVE-2025-52688 | Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading… | Patch early | 9.8 critical | 27.4% | 2025-07-16 |
| CVE-2020-11945 | An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are… | Patch early | 9.8 critical | 27.2% | 2020-04-23 |
| CVE-2017-11389 | Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-f… | Patch early | 9.8 critical | 27.2% | 2017-08-02 |
| CVE-2024-4323 | A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and… | Patch early | 9.8 critical | 27.2% | 2024-05-20 |
| CVE-2024-5765 | The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX actio… | Patch early | 9.8 critical | 27.2% | 2024-07-30 |
| CVE-2020-15906 | tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts. | Patch early | 9.8 critical | 27.2% | 2020-10-22 |
| CVE-2016-2148 | Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involvi… | Patch early | 9.8 critical | 27.1% | 2017-02-09 |
| CVE-2007-4559 | Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attacker… | Patch early | 9.8 critical | 27.1% | 2007-08-28 |
| CVE-2025-70161 | EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the s… | Patch early | 9.8 critical | 27.1% | 2026-01-09 |
| CVE-2022-37130 | In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is m… | Patch early | 9.8 critical | 26.9% | 2022-08-31 |
| CVE-2021-4119 | bookstack is vulnerable to Improper Access Control | Patch early | 9.8 critical | 26.9% | 2021-12-15 |
| CVE-2024-5452 | A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialize… | Patch early | 9.8 critical | 26.8% | 2024-06-06 |
| CVE-2022-35628 | A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3. | Patch early | 9.8 critical | 26.8% | 2022-07-12 |
| CVE-2018-20148 | In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLR… | Patch early | 9.8 critical | 26.8% | 2018-12-14 |
| CVE-2024-27172 | Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL. | Patch early | 9.8 critical | 26.8% | 2024-06-14 |
| CVE-2019-9827 | Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host vi… | Patch early | 9.8 critical | 26.8% | 2019-07-03 |
| CVE-2017-6403 | An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username… | Patch early | 9.8 critical | 26.7% | 2017-03-02 |
| CVE-2019-12256 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of… | Patch early | 9.8 critical | 26.6% | 2019-08-09 |
| CVE-2020-8840 | FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiCo… | Patch early | 9.8 critical | 26.6% | 2020-02-10 |
| CVE-2023-21689 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Patch early | 9.8 critical | 26.5% | 2023-02-14 |
| CVE-2025-11201 | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a… | Patch early | 9.8 critical | 26.5% | 2025-10-29 |
| CVE-2016-0705 | Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remo… | Patch early | 9.8 critical | 26.3% | 2016-03-03 |
| CVE-2020-24589 | The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks. | Patch early | 9.1 critical | 26.3% | 2020-08-21 |
| CVE-2017-2805 | An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially cr… | Patch early | 9.8 critical | 26.2% | 2017-06-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt