CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,567 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,739 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-27135 | xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combin… | In your normal cycle | 9.8 critical | 7.8% | 2021-02-10 |
| CVE-2017-2788 | A buffer overflows exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the v… | In your normal cycle | 10.0 critical | 7.8% | 2017-03-10 |
| CVE-2019-0219 | A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafte… | In your normal cycle | 9.8 critical | 7.8% | 2020-01-14 |
| CVE-2018-19409 | An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used. | In your normal cycle | 9.8 critical | 7.8% | 2018-11-21 |
| CVE-2022-22955 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious a… | In your normal cycle | 9.8 critical | 7.8% | 2022-04-13 |
| CVE-2016-15043 | The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions… | In your normal cycle | 9.8 critical | 7.8% | 2025-07-19 |
| CVE-2016-1903 | The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remot… | In your normal cycle | 9.1 critical | 7.8% | 2016-01-19 |
| CVE-2020-9347 | Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export… | In your normal cycle | 9.8 critical | 7.8% | 2020-03-16 |
| CVE-2020-4682 | IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserializat… | In your normal cycle | 9.8 critical | 7.8% | 2021-01-28 |
| CVE-2016-1283 | The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R… | In your normal cycle | 9.8 critical | 7.8% | 2016-01-03 |
| CVE-2019-15000 | The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed… | In your normal cycle | 9.8 critical | 7.8% | 2019-09-19 |
| CVE-2019-1010228 | OFFIS.de DCMTK 3.6.3 and below is affected by: Buffer Overflow. The impact is: Possible code execution and confirmed Denial of Service. The component… | In your normal cycle | 9.8 critical | 7.8% | 2019-07-22 |
| CVE-2018-0315 | A vulnerability in the authentication, authorization, and accounting (AAA) security services of Cisco IOS XE Software could allow an unauthenticated,… | In your normal cycle | 9.8 critical | 7.8% | 2018-06-07 |
| CVE-2022-22282 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an… | In your normal cycle | 9.8 critical | 7.8% | 2022-05-13 |
| CVE-2019-14895 | A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw cou… | In your normal cycle | 9.8 critical | 7.8% | 2019-11-29 |
| CVE-2018-17191 | Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the na… | In your normal cycle | 9.8 critical | 7.8% | 2018-12-31 |
| CVE-2021-26894 | Windows DNS Server Remote Code Execution Vulnerability | In your normal cycle | 9.8 critical | 7.8% | 2021-03-11 |
| CVE-2021-26895 | Windows DNS Server Remote Code Execution Vulnerability | In your normal cycle | 9.8 critical | 7.8% | 2021-03-11 |
| CVE-2016-4473 | /ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CV… | In your normal cycle | 9.8 critical | 7.8% | 2017-06-08 |
| CVE-2017-5651 | In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing… | In your normal cycle | 9.8 critical | 7.8% | 2017-04-17 |
| CVE-2014-1524 | The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonke… | In your normal cycle | 9.8 critical | 7.7% | 2014-04-30 |
| CVE-2022-32094 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php. | In your normal cycle | 9.8 critical | 7.7% | 2022-07-01 |
| CVE-2017-8948 | A Remote Bypass Security Restriction vulnerability in HPE Network Node Manager i (NNMi) Software versions v10.0x, v10.1x, v10.2x was found. | In your normal cycle | 9.8 critical | 7.7% | 2018-02-15 |
| CVE-2018-14826 | Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with a speciall… | In your normal cycle | 9.8 critical | 7.7% | 2018-10-02 |
| CVE-2018-15353 | A Buffer Overflow exploited through web interface by remote attacker can cause remote code execution in Kraftway 24F2XG Router firmware 3.5.30.1118. | In your normal cycle | 9.8 critical | 7.7% | 2018-08-17 |
| CVE-2021-35003 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer C90 1.0.6 Build 20200114 rel.73164(55… | In your normal cycle | 9.8 critical | 7.7% | 2022-01-21 |
| CVE-2021-35004 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link TL-WA1201 1.0.1 Build 20200709 rel.66244(555… | In your normal cycle | 9.8 critical | 7.7% | 2022-01-21 |
| CVE-2022-32207 | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a… | In your normal cycle | 9.8 critical | 7.7% | 2022-07-07 |
| CVE-2016-3149 | Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execute arbitra… | In your normal cycle | 9.8 critical | 7.7% | 2017-01-12 |
| CVE-2022-26499 | An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces su… | In your normal cycle | 9.1 critical | 7.7% | 2022-04-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt