CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,997 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,768 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-1998 | HPE Service Manager (SM) 9.3x before 9.35 P4 and 9.4x before 9.41.P2 allows remote attackers to execute arbitrary commands via a crafted serialized Ja… | In your normal cycle | 9.8 critical | 6.8% | 2016-03-22 |
| CVE-2016-1291 | Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary… | In your normal cycle | 9.8 critical | 6.8% | 2016-04-06 |
| CVE-2024-32735 | An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote… | In your normal cycle | 9.8 critical | 6.8% | 2024-05-14 |
| CVE-2021-42099 | Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution. | In your normal cycle | 9.8 critical | 6.8% | 2021-11-30 |
| CVE-2020-11973 | Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users sho… | In your normal cycle | 9.8 critical | 6.8% | 2020-05-14 |
| CVE-2024-55964 | An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution… | In your normal cycle | 9.8 critical | 6.8% | 2025-03-26 |
| CVE-2018-8847 | Eaton 9000X DriveA versions 2.0.29 and prior has a stack-based buffer overflow vulnerability, which may allow remote code execution. | In your normal cycle | 9.8 critical | 6.8% | 2018-07-13 |
| CVE-2020-13802 | Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification. | In your normal cycle | 9.8 critical | 6.8% | 2020-09-02 |
| CVE-2019-20478 | In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other… | In your normal cycle | 9.8 critical | 6.8% | 2020-02-19 |
| CVE-2024-41473 | Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac | In your normal cycle | 9.8 critical | 6.7% | 2024-07-25 |
| CVE-2018-1144 | A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to prox… | In your normal cycle | 9.8 critical | 6.7% | 2018-04-19 |
| CVE-2023-2437 | The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verificat… | In your normal cycle | 9.8 critical | 6.7% | 2023-11-22 |
| CVE-2021-34624 | A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible… | In your normal cycle | 9.8 critical | 6.7% | 2021-07-07 |
| CVE-2019-1212 | A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. An attacker who successfully ex… | In your normal cycle | 9.8 critical | 6.7% | 2019-08-14 |
| CVE-2018-18649 | An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It a… | In your normal cycle | 9.8 critical | 6.7% | 2018-11-29 |
| CVE-2022-28005 | An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse imprope… | In your normal cycle | 9.8 critical | 6.7% | 2022-05-06 |
| CVE-2020-12640 | Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.p… | In your normal cycle | 9.8 critical | 6.7% | 2020-05-04 |
| CVE-2018-20114 | On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can occur in the soap.cgi service… | In your normal cycle | 9.8 critical | 6.7% | 2019-01-02 |
| CVE-2015-5628 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and ea… | In your normal cycle | 9.8 critical | 6.7% | 2020-02-05 |
| CVE-2020-36242 | In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an int… | In your normal cycle | 9.1 critical | 6.7% | 2021-02-07 |
| CVE-2015-8557 | The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands… | In your normal cycle | 9.0 critical | 6.7% | 2016-01-08 |
| CVE-2019-12519 | An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function u… | In your normal cycle | 9.8 critical | 6.7% | 2020-04-15 |
| CVE-2018-12882 | exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it clo… | In your normal cycle | 9.8 critical | 6.7% | 2018-06-26 |
| CVE-2019-3395 | The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5… | In your normal cycle | 9.8 critical | 6.7% | 2019-03-25 |
| CVE-2015-8980 | The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. | In your normal cycle | 9.8 critical | 6.7% | 2019-11-04 |
| CVE-2025-11418 | A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1. This issue affects the function formWrlsafeset of the file /goform/AdvSetWrlsa… | In your normal cycle | 9.8 critical | 6.7% | 2025-10-08 |
| CVE-2022-36977 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication… | In your normal cycle | 9.8 critical | 6.7% | 2023-03-29 |
| CVE-2019-17133 | In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow. | In your normal cycle | 9.8 critical | 6.7% | 2019-10-04 |
| CVE-2018-8018 | In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deserializ… | In your normal cycle | 9.8 critical | 6.7% | 2018-07-20 |
| CVE-2017-16510 | WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQL… | In your normal cycle | 9.8 critical | 6.7% | 2017-11-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt