CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,997 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,768 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-11491 | ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution. | In your normal cycle | 9.8 critical | 6.7% | 2018-07-25 |
| CVE-2021-25032 | The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation a… | In your normal cycle | 9.8 critical | 6.7% | 2022-01-10 |
| CVE-2016-3598 | Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availabil… | In your normal cycle | 9.6 critical | 6.7% | 2016-07-21 |
| CVE-2016-1997 | HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands… | In your normal cycle | 9.8 critical | 6.7% | 2016-03-22 |
| CVE-2021-36888 | Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.… | In your normal cycle | 9.8 critical | 6.7% | 2021-12-15 |
| CVE-2019-12594 | DOSBox 0.74-2 has Incorrect Access Control. | In your normal cycle | 9.8 critical | 6.7% | 2019-07-02 |
| CVE-2016-10195 | The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_le… | In your normal cycle | 9.8 critical | 6.7% | 2017-03-15 |
| CVE-2020-10948 | Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a different… | In your normal cycle | 9.8 critical | 6.7% | 2020-04-01 |
| CVE-2016-2195 | Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibl… | In your normal cycle | 9.8 critical | 6.7% | 2016-05-13 |
| CVE-2021-22945 | When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory ar… | In your normal cycle | 9.1 critical | 6.7% | 2021-09-23 |
| CVE-2026-3485 | A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument… | In your normal cycle | 9.8 critical | 6.7% | 2026-03-03 |
| CVE-2013-5616 | Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2,… | In your normal cycle | 9.8 critical | 6.7% | 2013-12-11 |
| CVE-2024-50667 | The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The… | In your normal cycle | 9.8 critical | 6.7% | 2024-11-11 |
| CVE-2019-7117 | Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and e… | In your normal cycle | 9.8 critical | 6.7% | 2019-05-23 |
| CVE-2018-13797 | The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather t… | In your normal cycle | 9.8 critical | 6.7% | 2018-07-10 |
| CVE-2025-14879 | A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange of the component HTTP Request… | In your normal cycle | 9.8 critical | 6.7% | 2025-12-18 |
| CVE-2018-8794 | rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and… | In your normal cycle | 9.8 critical | 6.7% | 2019-02-05 |
| CVE-2016-7413 | Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers… | In your normal cycle | 9.8 critical | 6.7% | 2016-09-17 |
| CVE-2019-7779 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015… | In your normal cycle | 9.8 critical | 6.6% | 2019-05-22 |
| CVE-2022-20472 | In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execu… | In your normal cycle | 9.8 critical | 6.6% | 2022-12-13 |
| CVE-2021-4436 | The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJA… | In your normal cycle | 9.8 critical | 6.6% | 2024-02-05 |
| CVE-2019-10647 | ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage… | In your normal cycle | 9.8 critical | 6.6% | 2019-03-30 |
| CVE-2016-2242 | Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php. | In your normal cycle | 9.8 critical | 6.6% | 2017-01-23 |
| CVE-2026-11499 | A vulnerability was determined in Tenda HG7, HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBL… | In your normal cycle | 9.8 critical | 6.6% | 2026-06-08 |
| CVE-2016-1985 | HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to t… | In your normal cycle | 10.0 critical | 6.6% | 2016-01-30 |
| CVE-2019-7260 | Linear eMerge E3-Series devices have Cleartext Credentials in a Database. | In your normal cycle | 9.8 critical | 6.6% | 2019-07-02 |
| CVE-2021-31758 | An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setportList allo… | In your normal cycle | 9.8 critical | 6.6% | 2021-05-07 |
| CVE-2022-31181 | PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability… | In your normal cycle | 9.8 critical | 6.6% | 2022-08-01 |
| CVE-2016-6937 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 6.6% | 2016-09-17 |
| CVE-2026-24848 | OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() m… | In your normal cycle | 9.9 critical | 6.6% | 2026-03-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt