CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,590 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,743 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-17066 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functio… | In your normal cycle | 9.8 critical | 7.3% | 2018-09-15 |
| CVE-2016-9053 | An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server 3.10.0.3. A special… | In your normal cycle | 9.8 critical | 7.2% | 2017-02-21 |
| CVE-2025-24865 | The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retr… | In your normal cycle | 10.0 critical | 7.2% | 2025-02-13 |
| CVE-2019-11994 | A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600… | In your normal cycle | 9.8 critical | 7.2% | 2020-01-03 |
| CVE-2020-24639 | There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airwa… | In your normal cycle | 9.8 critical | 7.2% | 2021-01-15 |
| CVE-2021-41646 | Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasse… | In your normal cycle | 9.8 critical | 7.2% | 2021-10-29 |
| CVE-2024-20450 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series… | In your normal cycle | 9.8 critical | 7.2% | 2024-08-07 |
| CVE-2023-37924 | Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now w… | In your normal cycle | 9.8 critical | 7.2% | 2023-11-22 |
| CVE-2020-11982 | An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) d… | In your normal cycle | 9.8 critical | 7.2% | 2020-07-17 |
| CVE-2022-31976 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request. | In your normal cycle | 9.8 critical | 7.2% | 2022-06-02 |
| CVE-2022-31977 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team. | In your normal cycle | 9.8 critical | 7.2% | 2022-06-02 |
| CVE-2022-31978 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry. | In your normal cycle | 9.8 critical | 7.2% | 2022-06-02 |
| CVE-2014-125117 | A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploit… | In your normal cycle | 9.8 critical | 7.2% | 2025-07-25 |
| CVE-2022-24049 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11… | In your normal cycle | 9.8 critical | 7.2% | 2022-02-18 |
| CVE-2024-28189 | Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacke… | In your normal cycle | 10.0 critical | 7.2% | 2024-04-18 |
| CVE-2017-16740 | A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier. T… | In your normal cycle | 10.0 critical | 7.2% | 2018-01-09 |
| CVE-2017-12633 | The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De… | In your normal cycle | 9.8 critical | 7.2% | 2017-11-15 |
| CVE-2017-12634 | The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-… | In your normal cycle | 9.8 critical | 7.2% | 2017-11-15 |
| CVE-2022-34598 | The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary commands. | In your normal cycle | 9.8 critical | 7.2% | 2022-07-06 |
| CVE-2016-6949 | Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Ac… | In your normal cycle | 9.8 critical | 7.2% | 2016-10-13 |
| CVE-2017-8923 | The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length… | In your normal cycle | 9.8 critical | 7.2% | 2017-05-12 |
| CVE-2024-51092 | LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsC… | In your normal cycle | 9.1 critical | 7.2% | 2026-05-08 |
| CVE-2019-1010060 | NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were… | In your normal cycle | 9.8 critical | 7.2% | 2019-07-16 |
| CVE-2018-5097 | A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content d… | In your normal cycle | 9.8 critical | 7.2% | 2018-06-11 |
| CVE-2018-5104 | A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploi… | In your normal cycle | 9.8 critical | 7.2% | 2018-06-11 |
| CVE-2022-4873 | On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of… | In your normal cycle | 9.8 critical | 7.2% | 2023-01-11 |
| CVE-2026-23523 | Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install… | In your normal cycle | 9.6 critical | 7.2% | 2026-01-16 |
| CVE-2026-33453 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's cam… | In your normal cycle | 10.0 critical | 7.2% | 2026-04-27 |
| CVE-2004-0434 | k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing l… | In your normal cycle | 9.8 critical | 7.2% | 2004-07-07 |
| CVE-2024-6385 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting f… | In your normal cycle | 9.6 critical | 7.2% | 2024-07-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt