CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,769 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,848 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-28769 | The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)… | In your normal cycle | 9.8 critical | 5.4% | 2023-04-27 |
| CVE-2016-6295 | ext/snmp/snmp.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 improperly interacts with the unserialize implementation and garbage c… | In your normal cycle | 9.8 critical | 5.4% | 2016-07-25 |
| CVE-2019-5684 | NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of… | In your normal cycle | 10.0 critical | 5.4% | 2019-08-06 |
| CVE-2021-23639 | The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter conten… | In your normal cycle | 9.8 critical | 5.4% | 2021-12-10 |
| CVE-2016-10145 | Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy. | In your normal cycle | 9.8 critical | 5.4% | 2017-03-24 |
| CVE-2022-45005 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function. | In your normal cycle | 9.8 critical | 5.4% | 2022-12-13 |
| CVE-2019-5909 | License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4.… | In your normal cycle | 9.8 critical | 5.4% | 2019-02-13 |
| CVE-2019-5347 | A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | In your normal cycle | 9.8 critical | 5.4% | 2019-06-05 |
| CVE-2021-4449 | The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions… | In your normal cycle | 9.8 critical | 5.4% | 2024-10-16 |
| CVE-2015-0857 | Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within… | In your normal cycle | 9.8 critical | 5.4% | 2016-05-06 |
| CVE-2017-10622 | An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based at… | In your normal cycle | 9.8 critical | 5.4% | 2017-10-13 |
| CVE-2025-22604 | Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject mal… | In your normal cycle | 9.1 critical | 5.4% | 2025-01-27 |
| CVE-2020-8159 | There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulti… | In your normal cycle | 9.8 critical | 5.4% | 2020-05-12 |
| CVE-2018-14790 | Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. A buffer over-rea… | In your normal cycle | 9.8 critical | 5.4% | 2018-10-01 |
| CVE-2019-19646 | pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns. | In your normal cycle | 9.8 critical | 5.4% | 2019-12-09 |
| CVE-2020-27956 | An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execu… | In your normal cycle | 9.8 critical | 5.4% | 2020-10-28 |
| CVE-2020-24032 | tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone. | In your normal cycle | 9.8 critical | 5.4% | 2020-08-18 |
| CVE-2019-17531 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a… | In your normal cycle | 9.8 critical | 5.4% | 2019-10-12 |
| CVE-2022-32845 | This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able t… | In your normal cycle | 10.0 critical | 5.4% | 2022-09-23 |
| CVE-2023-3867 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds read in smb2_sess_setup ksmbd does not consider the cas… | In your normal cycle | 9.1 critical | 5.4% | 2025-08-16 |
| CVE-2025-65212 | An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie veri… | In your normal cycle | 9.8 critical | 5.4% | 2026-01-06 |
| CVE-2021-26541 | The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability. | In your normal cycle | 9.8 critical | 5.4% | 2021-02-08 |
| CVE-2020-10938 | GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c. | In your normal cycle | 9.8 critical | 5.4% | 2020-03-24 |
| CVE-2022-28571 | D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli. | In your normal cycle | 9.8 critical | 5.3% | 2022-05-02 |
| CVE-2014-3445 | backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass aut… | In your normal cycle | 9.8 critical | 5.3% | 2020-01-28 |
| CVE-2015-1006 | A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versio… | In your normal cycle | 9.8 critical | 5.3% | 2019-05-10 |
| CVE-2022-39227 | python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulti… | In your normal cycle | 9.1 critical | 5.3% | 2022-09-23 |
| CVE-2019-1917 | A vulnerability in the REST API interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentic… | In your normal cycle | 9.1 critical | 5.3% | 2019-07-17 |
| CVE-2016-2196 | Heap-based buffer overflow in the P-521 reduction function in Botan 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (memory… | In your normal cycle | 9.8 critical | 5.3% | 2016-05-13 |
| CVE-2020-35458 | An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in t… | In your normal cycle | 9.8 critical | 5.3% | 2021-01-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt