CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,732 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-9707 | The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json… | In your normal cycle | 9.8 critical | 9.1% | 2024-10-11 |
| CVE-2020-12002 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of prope… | In your normal cycle | 9.8 critical | 9.1% | 2020-05-08 |
| CVE-2021-1610 | Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Route… | In your normal cycle | 9.8 critical | 9.1% | 2021-08-04 |
| CVE-2018-1722 | IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are ru… | In your normal cycle | 10.0 critical | 9% | 2018-08-24 |
| CVE-2022-0785 | The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the g… | In your normal cycle | 9.8 critical | 9% | 2022-04-18 |
| CVE-2025-50989 | OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). T… | In your normal cycle | 9.1 critical | 9% | 2025-08-27 |
| CVE-2018-1000122 | A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of servi… | In your normal cycle | 9.1 critical | 9% | 2018-03-14 |
| CVE-2024-21534 | All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute ar… | In your normal cycle | 9.8 critical | 9% | 2024-10-11 |
| CVE-2022-26887 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_loopmapHandler.ashx. This allow… | In your normal cycle | 9.8 critical | 9% | 2022-03-29 |
| CVE-2025-13915 | IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized acces… | In your normal cycle | 9.8 critical | 9% | 2025-12-26 |
| CVE-2022-25445 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function. | In your normal cycle | 9.8 critical | 9% | 2022-03-18 |
| CVE-2019-10991 | In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the le… | In your normal cycle | 9.8 critical | 9% | 2019-06-28 |
| CVE-2023-49007 | In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd. | In your normal cycle | 9.8 critical | 9% | 2023-12-08 |
| CVE-2024-56337 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, fr… | In your normal cycle | 9.8 critical | 9% | 2024-12-20 |
| CVE-2019-12261 | Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urge… | In your normal cycle | 9.8 critical | 9% | 2019-08-09 |
| CVE-2026-19632 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… | In your normal cycle | 9.8 critical | 9% | 2026-08-26 |
| CVE-2021-38306 | Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/plu… | In your normal cycle | 9.8 critical | 9% | 2021-08-24 |
| CVE-2011-2767 | mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the doc… | In your normal cycle | 9.8 critical | 8.9% | 2018-08-26 |
| CVE-2017-15041 | Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it is possible to arrange things so that exampl… | In your normal cycle | 9.8 critical | 8.9% | 2017-10-05 |
| CVE-2024-43639 | Windows KDC Proxy Remote Code Execution Vulnerability | In your normal cycle | 9.8 critical | 8.9% | 2024-11-12 |
| CVE-2025-57773 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JND… | In your normal cycle | 9.8 critical | 8.9% | 2025-08-25 |
| CVE-2026-20181 | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating syste… | In your normal cycle | 9.1 critical | 8.9% | 2026-06-17 |
| CVE-2024-27903 | OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in w… | In your normal cycle | 9.8 critical | 8.9% | 2024-07-08 |
| CVE-2019-20444 | HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorr… | In your normal cycle | 9.1 critical | 8.9% | 2020-01-29 |
| CVE-2016-9634 | Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote at… | In your normal cycle | 9.8 critical | 8.9% | 2017-01-27 |
| CVE-2016-9635 | Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote at… | In your normal cycle | 9.8 critical | 8.9% | 2017-01-27 |
| CVE-2022-3980 | An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises… | In your normal cycle | 9.8 critical | 8.9% | 2022-11-16 |
| CVE-2016-0868 | Stack-based buffer overflow on Rockwell Automation Allen-Bradley MicroLogix 1100 devices A through 15.000 and B before 15.002 allows remote attackers… | In your normal cycle | 9.8 critical | 8.9% | 2016-01-28 |
| CVE-2017-3063 | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the ActionScript2 NetStream class. Successful e… | In your normal cycle | 9.8 critical | 8.9% | 2017-04-12 |
| CVE-2022-28082 | Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList. | In your normal cycle | 9.8 critical | 8.9% | 2022-05-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt