CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,708 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,840 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-7689 | A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0. | In your normal cycle | 9.8 critical | 5.5% | 2017-04-11 |
| CVE-2017-12865 | Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitr… | In your normal cycle | 9.8 critical | 5.5% | 2017-08-29 |
| CVE-2017-0915 | Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execut… | In your normal cycle | 9.8 critical | 5.5% | 2018-03-21 |
| CVE-2017-0916 | Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting i… | In your normal cycle | 9.8 critical | 5.5% | 2018-03-21 |
| CVE-2022-24193 | CasaOS before v0.2.7 was discovered to contain a command injection vulnerability. | In your normal cycle | 9.8 critical | 5.5% | 2022-03-10 |
| CVE-2022-26136 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps.… | In your normal cycle | 9.8 critical | 5.5% | 2022-07-20 |
| CVE-2014-1477 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and… | In your normal cycle | 9.8 critical | 5.5% | 2014-02-06 |
| CVE-2014-9761 | Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of ser… | In your normal cycle | 9.8 critical | 5.5% | 2016-04-19 |
| CVE-2023-3077 | The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injec… | In your normal cycle | 9.8 critical | 5.5% | 2023-07-10 |
| CVE-2016-8575 | The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2017-5482. | In your normal cycle | 9.8 critical | 5.5% | 2017-01-28 |
| CVE-2017-5342 | In tcpdump before 4.9.0, a bug in multiple protocol parsers (Geneve, GRE, NSH, OTV, VXLAN and VXLAN GPE) could cause a buffer overflow in print-ether.… | In your normal cycle | 9.8 critical | 5.5% | 2017-01-28 |
| CVE-2017-5482 | The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575. | In your normal cycle | 9.8 critical | 5.5% | 2017-01-28 |
| CVE-2016-3551 | Unspecified vulnerability in the Oracle Web Services component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, and 12.2.1.0.0 allows r… | In your normal cycle | 9.8 critical | 5.5% | 2016-10-25 |
| CVE-2016-4024 | Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which… | In your normal cycle | 9.8 critical | 5.5% | 2016-05-13 |
| CVE-2020-6967 | In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exp… | In your normal cycle | 9.8 critical | 5.5% | 2020-03-23 |
| CVE-2026-26216 | Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks param… | In your normal cycle | 10.0 critical | 5.5% | 2026-02-12 |
| CVE-2016-0940 | Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Ac… | In your normal cycle | 9.8 critical | 5.5% | 2016-01-14 |
| CVE-2020-16204 | The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as root on th… | In your normal cycle | 9.8 critical | 5.5% | 2020-09-01 |
| CVE-2010-5325 | Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of ser… | In your normal cycle | 9.8 critical | 5.5% | 2016-04-15 |
| CVE-2018-1282 | This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup tha… | In your normal cycle | 9.1 critical | 5.5% | 2018-04-05 |
| CVE-2018-18628 | An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize… | In your normal cycle | 9.8 critical | 5.5% | 2018-10-23 |
| CVE-2017-11462 | Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of securit… | In your normal cycle | 9.8 critical | 5.5% | 2017-09-13 |
| CVE-2016-6290 | ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which… | In your normal cycle | 9.8 critical | 5.5% | 2016-07-25 |
| CVE-2016-3443 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via v… | In your normal cycle | 9.6 critical | 5.5% | 2016-04-21 |
| CVE-2016-3444 | Unspecified vulnerability in the Oracle Retail Integration Bus component in Oracle Retail Applications 13.0, 13.1, 13.2, 14.0, 14.1, and 15.0 allows r… | In your normal cycle | 9.8 critical | 5.5% | 2016-07-21 |
| CVE-2016-3468 | Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows r… | In your normal cycle | 9.8 critical | 5.5% | 2016-07-21 |
| CVE-2016-3613 | Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 4.63, 4.71, and 5.2 allows remote attackers to affect… | In your normal cycle | 9.8 critical | 5.5% | 2016-07-21 |
| CVE-2017-6747 | A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local a… | In your normal cycle | 9.8 critical | 5.5% | 2017-08-07 |
| CVE-2022-26585 | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list. | In your normal cycle | 9.8 critical | 5.5% | 2022-04-05 |
| CVE-2020-10224 | An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be expl… | In your normal cycle | 9.8 critical | 5.5% | 2020-03-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt