CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,964 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,763 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-1953 | Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes… | In your normal cycle | 10.0 critical | 6.8% | 2020-03-13 |
| CVE-2018-0253 | A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arb… | In your normal cycle | 9.8 critical | 6.8% | 2018-05-02 |
| CVE-2023-37266 | CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentica… | In your normal cycle | 9.8 critical | 6.8% | 2023-07-17 |
| CVE-2016-7127 | The imagegammacorrect function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate gamma values, which allows remote… | In your normal cycle | 9.8 critical | 6.8% | 2016-09-12 |
| CVE-2016-7129 | The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service… | In your normal cycle | 9.8 critical | 6.8% | 2016-09-12 |
| CVE-2016-7414 | The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_filesize field is large enough… | In your normal cycle | 9.8 critical | 6.8% | 2016-09-17 |
| CVE-2016-7417 | ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type,… | In your normal cycle | 9.8 critical | 6.8% | 2016-09-17 |
| CVE-2017-3792 | A vulnerability in a proprietary device driver in the kernel of Cisco TelePresence Multipoint Control Unit (MCU) Software could allow an unauthenticat… | In your normal cycle | 9.8 critical | 6.8% | 2017-02-01 |
| CVE-2023-5204 | The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient e… | In your normal cycle | 9.8 critical | 6.8% | 2023-10-19 |
| CVE-2016-10152 | The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file f… | In your normal cycle | 9.8 critical | 6.8% | 2017-03-28 |
| CVE-2018-15427 | A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (UC… | In your normal cycle | 9.8 critical | 6.8% | 2018-10-05 |
| CVE-2019-10126 | A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c… | In your normal cycle | 9.8 critical | 6.8% | 2019-06-14 |
| CVE-2024-5805 | Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.0… | In your normal cycle | 9.1 critical | 6.8% | 2024-06-25 |
| CVE-2020-27251 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker… | In your normal cycle | 9.8 critical | 6.8% | 2020-11-26 |
| CVE-2020-17407 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authenti… | In your normal cycle | 9.8 critical | 6.8% | 2020-10-13 |
| CVE-2025-14156 | The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is d… | In your normal cycle | 9.8 critical | 6.8% | 2025-12-15 |
| CVE-2019-1449 | A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which could lead… | In your normal cycle | 9.8 critical | 6.8% | 2019-11-12 |
| CVE-2024-12108 | In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API. | In your normal cycle | 9.6 critical | 6.8% | 2024-12-31 |
| CVE-2016-7398 | A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well… | In your normal cycle | 9.8 critical | 6.8% | 2019-09-06 |
| CVE-2017-18377 | An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in… | In your normal cycle | 9.8 critical | 6.8% | 2019-06-11 |
| CVE-2018-20179 | rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_process() a… | In your normal cycle | 9.8 critical | 6.8% | 2019-03-15 |
| CVE-2016-3737 | The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, relate… | In your normal cycle | 9.8 critical | 6.8% | 2016-08-02 |
| CVE-2023-42117 | Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… | In your normal cycle | 9.8 critical | 6.8% | 2024-05-03 |
| CVE-2023-46221 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | In your normal cycle | 9.8 critical | 6.8% | 2023-12-19 |
| CVE-2023-46222 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | In your normal cycle | 9.8 critical | 6.8% | 2023-12-19 |
| CVE-2023-46223 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | In your normal cycle | 9.8 critical | 6.8% | 2023-12-19 |
| CVE-2023-46224 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | In your normal cycle | 9.8 critical | 6.8% | 2023-12-19 |
| CVE-2023-46258 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | In your normal cycle | 9.8 critical | 6.8% | 2023-12-19 |
| CVE-2016-2099 | Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspec… | In your normal cycle | 9.8 critical | 6.8% | 2016-05-13 |
| CVE-2022-27984 | CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/r… | In your normal cycle | 9.8 critical | 6.8% | 2022-04-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt