CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,317 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,711 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-40851 | Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat. | In your normal cycle | 9.8 critical | 9.7% | 2022-09-23 |
| CVE-2016-5772 | Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x bef… | In your normal cycle | 9.8 critical | 9.7% | 2016-08-07 |
| CVE-2018-4013 | An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A special… | In your normal cycle | 9.8 critical | 9.7% | 2018-10-19 |
| CVE-2017-5005 | Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.31… | In your normal cycle | 9.8 critical | 9.7% | 2017-01-02 |
| CVE-2016-3312 | ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtain… | In your normal cycle | 9.1 critical | 9.7% | 2016-08-09 |
| CVE-2017-13715 | The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are init… | In your normal cycle | 9.8 critical | 9.7% | 2017-08-29 |
| CVE-2018-18492 | A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. T… | In your normal cycle | 9.8 critical | 9.6% | 2019-02-28 |
| CVE-2021-33912 | libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e… | In your normal cycle | 9.8 critical | 9.6% | 2022-01-19 |
| CVE-2021-33913 | libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail mess… | In your normal cycle | 9.8 critical | 9.6% | 2022-01-19 |
| CVE-2016-5768 | Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5.6.x befor… | In your normal cycle | 9.8 critical | 9.6% | 2016-08-07 |
| CVE-2015-5739 | The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct… | In your normal cycle | 9.8 critical | 9.6% | 2017-10-18 |
| CVE-2022-4063 | The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the… | In your normal cycle | 9.8 critical | 9.6% | 2022-12-19 |
| CVE-2018-3937 | An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.… | In your normal cycle | 9.1 critical | 9.6% | 2018-08-14 |
| CVE-2025-8489 | The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalati… | In your normal cycle | 9.8 critical | 9.6% | 2025-10-31 |
| CVE-2018-12387 | A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by… | In your normal cycle | 9.1 critical | 9.6% | 2018-10-18 |
| CVE-2013-7459 | Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute… | In your normal cycle | 9.8 critical | 9.6% | 2017-02-15 |
| CVE-2020-7199 | A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software… | In your normal cycle | 9.8 critical | 9.6% | 2020-12-02 |
| CVE-2003-0356 | Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary… | In your normal cycle | 9.8 critical | 9.6% | 2003-06-09 |
| CVE-2025-39946 | In the Linux kernel, the following vulnerability has been resolved: tls: make sure to abort the stream if headers are bogus Normally we wait for the… | In your normal cycle | 9.8 critical | 9.6% | 2025-10-04 |
| CVE-2019-20504 | service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell m… | In your normal cycle | 9.8 critical | 9.6% | 2020-03-09 |
| CVE-2024-8785 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry… | In your normal cycle | 9.8 critical | 9.5% | 2024-12-02 |
| CVE-2021-37761 | Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution. | In your normal cycle | 9.8 critical | 9.5% | 2021-09-27 |
| CVE-2021-37928 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | In your normal cycle | 9.8 critical | 9.5% | 2021-10-07 |
| CVE-2021-37929 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | In your normal cycle | 9.8 critical | 9.5% | 2021-10-07 |
| CVE-2021-37930 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | In your normal cycle | 9.8 critical | 9.5% | 2021-10-07 |
| CVE-2021-37931 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | In your normal cycle | 9.8 critical | 9.5% | 2021-10-07 |
| CVE-2022-22280 | Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.3… | In your normal cycle | 9.8 critical | 9.5% | 2022-07-29 |
| CVE-2019-17146 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not req… | In your normal cycle | 9.8 critical | 9.5% | 2020-01-07 |
| CVE-2022-46475 | D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main function. | In your normal cycle | 9.8 critical | 9.5% | 2023-01-17 |
| CVE-2018-18313 | Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory. | In your normal cycle | 9.1 critical | 9.5% | 2018-12-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt