CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,590 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,743 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-15048 | AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manager/radius/server_ping.php endpo… | In your normal cycle | 9.8 critical | 7.4% | 2025-10-22 |
| CVE-2023-37265 | CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands a… | In your normal cycle | 9.8 critical | 7.4% | 2023-07-17 |
| CVE-2025-54382 | Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in th… | In your normal cycle | 9.6 critical | 7.4% | 2025-08-13 |
| CVE-2018-11788 | Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The f… | In your normal cycle | 9.8 critical | 7.3% | 2019-01-07 |
| CVE-2022-24292 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution. | In your normal cycle | 9.8 critical | 7.3% | 2022-03-23 |
| CVE-2022-24293 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution. | In your normal cycle | 9.8 critical | 7.3% | 2022-03-23 |
| CVE-2017-7828 | A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been freed while still in use. This res… | In your normal cycle | 9.8 critical | 7.3% | 2018-06-11 |
| CVE-2016-5770 | Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remo… | In your normal cycle | 9.8 critical | 7.3% | 2016-08-07 |
| CVE-2026-10187 | A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so… | In your normal cycle | 9.8 critical | 7.3% | 2026-05-31 |
| CVE-2023-32117 | Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This iss… | In your normal cycle | 9.8 critical | 7.3% | 2024-12-09 |
| CVE-2022-36978 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication… | In your normal cycle | 9.8 critical | 7.3% | 2023-03-29 |
| CVE-2019-14277 | Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XX… | In your normal cycle | 9.8 critical | 7.3% | 2019-07-26 |
| CVE-2018-5339 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions. | In your normal cycle | 9.8 critical | 7.3% | 2018-04-18 |
| CVE-2019-7968 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to ar… | In your normal cycle | 9.8 critical | 7.3% | 2019-08-26 |
| CVE-2018-14067 | Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command execution, via a crafted payload to th… | In your normal cycle | 9.8 critical | 7.3% | 2020-12-31 |
| CVE-2024-45434 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results fr… | In your normal cycle | 9.8 critical | 7.3% | 2025-09-12 |
| CVE-2016-10178 | An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command. | In your normal cycle | 9.8 critical | 7.3% | 2017-01-30 |
| CVE-2021-24943 | The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJA… | In your normal cycle | 9.8 critical | 7.3% | 2021-12-06 |
| CVE-2017-14854 | A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution. The vulnerability affects all versions… | In your normal cycle | 9.1 critical | 7.3% | 2019-06-03 |
| CVE-2018-8784 | FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that results in a memory corruption and… | In your normal cycle | 9.8 critical | 7.3% | 2018-11-29 |
| CVE-2018-8785 | FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress() that results in a memory corruption and probabl… | In your normal cycle | 9.8 critical | 7.3% | 2018-11-29 |
| CVE-2024-25110 | The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-afte… | In your normal cycle | 9.8 critical | 7.3% | 2024-02-12 |
| CVE-2021-42949 | The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to byp… | In your normal cycle | 9.8 critical | 7.3% | 2022-09-16 |
| CVE-2025-23061 | Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because… | In your normal cycle | 9.0 critical | 7.3% | 2025-01-15 |
| CVE-2021-24236 | The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to for… | In your normal cycle | 9.8 critical | 7.3% | 2021-05-06 |
| CVE-2014-0048 | An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways. | In your normal cycle | 9.8 critical | 7.3% | 2020-01-02 |
| CVE-2020-10683 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is pop… | In your normal cycle | 9.8 critical | 7.3% | 2020-05-01 |
| CVE-2015-8863 | Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded num… | In your normal cycle | 9.8 critical | 7.3% | 2016-05-06 |
| CVE-2025-68705 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerabil… | In your normal cycle | 9.8 critical | 7.3% | 2026-01-07 |
| CVE-2018-17930 | A stack-based buffer overflow vulnerability has been identified in Teledyne DALSA Sherlock Version 7.2.7.4 and prior, which may allow remote code exec… | In your normal cycle | 9.8 critical | 7.3% | 2018-11-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt