CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,829 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,870 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-12643 | A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass au… | In your normal cycle | 10.0 critical | 5.3% | 2019-08-28 |
| CVE-2021-3190 | The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag. | In your normal cycle | 9.8 critical | 5.3% | 2021-01-26 |
| CVE-2016-9137 | Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers… | In your normal cycle | 9.8 critical | 5.3% | 2017-01-04 |
| CVE-2020-29659 | A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowin… | In your normal cycle | 9.8 critical | 5.3% | 2020-12-09 |
| CVE-2014-8888 | The remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via… | In your normal cycle | 9.8 critical | 5.3% | 2018-04-12 |
| CVE-2016-7050 | SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Re… | In your normal cycle | 9.8 critical | 5.3% | 2017-06-08 |
| CVE-2022-43367 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function. | In your normal cycle | 9.8 critical | 5.3% | 2022-10-27 |
| CVE-2019-16871 | Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Exec… | In your normal cycle | 9.8 critical | 5.3% | 2019-12-19 |
| CVE-2026-41179 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to… | In your normal cycle | 9.8 critical | 5.3% | 2026-04-23 |
| CVE-2025-35028 | By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI… | In your normal cycle | 9.1 critical | 5.3% | 2025-11-30 |
| CVE-2017-16748 | An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and prior) using… | In your normal cycle | 9.8 critical | 5.3% | 2018-08-20 |
| CVE-2021-3773 | A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network a… | In your normal cycle | 9.8 critical | 5.3% | 2022-02-16 |
| CVE-2017-2518 | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | In your normal cycle | 9.8 critical | 5.3% | 2017-05-22 |
| CVE-2019-7489 | A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Emai… | In your normal cycle | 9.8 critical | 5.3% | 2019-12-23 |
| CVE-2017-3831 | A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass aut… | In your normal cycle | 9.8 critical | 5.3% | 2017-03-15 |
| CVE-2022-28033 | Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php | In your normal cycle | 9.8 critical | 5.3% | 2022-04-12 |
| CVE-2022-42040 | The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is… | In your normal cycle | 9.8 critical | 5.3% | 2022-10-11 |
| CVE-2020-24407 | Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. Th… | In your normal cycle | 9.1 critical | 5.3% | 2020-11-09 |
| CVE-2021-21884 | An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-craf… | In your normal cycle | 9.1 critical | 5.3% | 2021-12-22 |
| CVE-2015-8869 | OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive inf… | In your normal cycle | 9.1 critical | 5.3% | 2016-06-13 |
| CVE-2012-6068 | The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via t… | In your normal cycle | 9.8 critical | 5.3% | 2013-01-21 |
| CVE-2018-19990 | In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devices. In the… | In your normal cycle | 9.8 critical | 5.3% | 2019-05-13 |
| CVE-2019-0006 | A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on… | In your normal cycle | 9.8 critical | 5.3% | 2019-01-15 |
| CVE-2021-33911 | Zoho ManageEngine ADManager Plus before 7110 allows remote code execution. | In your normal cycle | 9.8 critical | 5.3% | 2021-07-17 |
| CVE-2019-10125 | An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event is… | In your normal cycle | 9.8 critical | 5.3% | 2019-03-27 |
| CVE-2019-9165 | SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and maliciou… | In your normal cycle | 9.8 critical | 5.3% | 2019-03-28 |
| CVE-2021-21783 | A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to… | In your normal cycle | 9.8 critical | 5.3% | 2021-03-25 |
| CVE-2019-15926 | An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and ath6kl_… | In your normal cycle | 9.1 critical | 5.3% | 2019-09-04 |
| CVE-2018-15764 | Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggered JMX serv… | In your normal cycle | 9.8 critical | 5.3% | 2018-09-28 |
| CVE-2017-12194 | A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could… | In your normal cycle | 9.8 critical | 5.2% | 2018-03-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt