CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,660 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,839 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-9000 | ArubaOS, all versions prior to 6.3.1.25, 6.4 prior to 6.4.4.16, 6.5.x prior to 6.5.1.9, 6.5.2, 6.5.3 prior to 6.5.3.3, 6.5.4 prior to 6.5.4.2, 8.x pri… | In your normal cycle | 9.8 critical | 5.7% | 2018-08-06 |
| CVE-2020-28908 | Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios. | In your normal cycle | 9.8 critical | 5.7% | 2021-05-24 |
| CVE-2022-45460 | Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow a… | In your normal cycle | 9.8 critical | 5.7% | 2023-03-28 |
| CVE-2021-0397 | In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no… | In your normal cycle | 9.8 critical | 5.7% | 2021-03-10 |
| CVE-2021-2302 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported versions that are affected are… | In your normal cycle | 9.8 critical | 5.7% | 2021-04-22 |
| CVE-2016-4346 | Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly… | In your normal cycle | 9.8 critical | 5.7% | 2016-05-22 |
| CVE-2021-27472 | A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may… | In your normal cycle | 10.0 critical | 5.7% | 2022-03-23 |
| CVE-2017-18342 | In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version… | In your normal cycle | 9.8 critical | 5.7% | 2018-06-27 |
| CVE-2026-4585 | A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy7… | In your normal cycle | 9.8 critical | 5.7% | 2026-03-23 |
| CVE-2020-11972 | Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users… | In your normal cycle | 9.8 critical | 5.7% | 2020-05-14 |
| CVE-2016-4898 | The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified atta… | In your normal cycle | 9.8 critical | 5.6% | 2017-04-13 |
| CVE-2016-4899 | The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified atta… | In your normal cycle | 9.8 critical | 5.6% | 2017-04-13 |
| CVE-2016-7411 | ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote attackers to cause a denial of s… | In your normal cycle | 9.8 critical | 5.6% | 2016-09-17 |
| CVE-2018-18473 | A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, a… | In your normal cycle | 9.8 critical | 5.6% | 2019-03-21 |
| CVE-2017-12739 | An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The int… | In your normal cycle | 9.8 critical | 5.6% | 2017-11-15 |
| CVE-2018-19282 | Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Pr… | In your normal cycle | 9.8 critical | 5.6% | 2019-04-04 |
| CVE-2014-9515 | Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted seria… | In your normal cycle | 9.8 critical | 5.6% | 2017-12-29 |
| CVE-2016-1946 | The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operation… | In your normal cycle | 9.8 critical | 5.6% | 2016-01-31 |
| CVE-2018-19702 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… | In your normal cycle | 9.8 critical | 5.6% | 2019-01-18 |
| CVE-2018-11229 | Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution… | In your normal cycle | 9.8 critical | 5.6% | 2018-06-08 |
| CVE-2024-45256 | An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypa… | In your normal cycle | 9.8 critical | 5.6% | 2024-08-26 |
| CVE-2016-2054 | Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code… | In your normal cycle | 9.8 critical | 5.6% | 2016-04-13 |
| CVE-2021-26600 | ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==). | In your normal cycle | 9.8 critical | 5.6% | 2022-03-28 |
| CVE-2025-14535 | A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. The… | In your normal cycle | 9.8 critical | 5.6% | 2025-12-11 |
| CVE-2017-8410 | An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections recei… | In your normal cycle | 9.8 critical | 5.6% | 2019-07-02 |
| CVE-2019-14892 | A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mali… | In your normal cycle | 9.8 critical | 5.6% | 2020-03-02 |
| CVE-2018-11221 | Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/upd… | In your normal cycle | 9.8 critical | 5.6% | 2018-06-16 |
| CVE-2014-9766 | Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (appl… | In your normal cycle | 9.8 critical | 5.6% | 2016-04-13 |
| CVE-2016-8276 | Buffer overflow in the Point-to-Point Protocol over Ethernet (PPPoE) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways… | In your normal cycle | 9.8 critical | 5.6% | 2016-10-03 |
| CVE-2017-11420 | Stack-based buffer overflow in ASUS_Discovery.c in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1… | In your normal cycle | 9.8 critical | 5.6% | 2017-07-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt