CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,829 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,870 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-23330 | All versions of package launchpad are vulnerable to Command Injection via stop. | In your normal cycle | 9.8 critical | 5.2% | 2021-02-01 |
| CVE-2018-18320 | An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has… | In your normal cycle | 9.8 critical | 5.2% | 2018-10-15 |
| CVE-2019-17669 | WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as… | In your normal cycle | 9.8 critical | 5.2% | 2019-10-17 |
| CVE-2018-15751 | SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-ap… | In your normal cycle | 9.8 critical | 5.2% | 2018-10-24 |
| CVE-2014-4678 | The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via… | In your normal cycle | 9.8 critical | 5.2% | 2020-02-20 |
| CVE-2021-3144 | In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions… | In your normal cycle | 9.1 critical | 5.2% | 2021-02-27 |
| CVE-2016-3690 | The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload. | In your normal cycle | 9.8 critical | 5.2% | 2017-06-08 |
| CVE-2018-15128 | An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulne… | In your normal cycle | 9.8 critical | 5.2% | 2019-05-13 |
| CVE-2019-3922 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent… | In your normal cycle | 9.8 critical | 5.2% | 2019-03-05 |
| CVE-2020-12278 | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate D… | In your normal cycle | 9.8 critical | 5.2% | 2020-04-27 |
| CVE-2020-3752 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… | In your normal cycle | 9.8 critical | 5.2% | 2020-02-13 |
| CVE-2020-11856 | Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow re… | In your normal cycle | 9.8 critical | 5.2% | 2020-09-22 |
| CVE-2014-9189 | Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6,… | In your normal cycle | 9.8 critical | 5.2% | 2019-03-25 |
| CVE-2017-12762 | In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can… | In your normal cycle | 9.8 critical | 5.2% | 2017-08-09 |
| CVE-2016-4322 | BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or po… | In your normal cycle | 9.8 critical | 5.2% | 2016-12-13 |
| CVE-2019-7629 | Stack-based buffer overflow in the strip_vt102_codes function in TinTin++ 2.01.6 and WinTin++ 2.01.6 allows remote attackers to execute arbitrary code… | In your normal cycle | 9.8 critical | 5.2% | 2019-02-18 |
| CVE-2022-36412 | In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be exec… | In your normal cycle | 9.8 critical | 5.2% | 2022-07-26 |
| CVE-2019-11068 | libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a… | In your normal cycle | 9.8 critical | 5.2% | 2019-04-10 |
| CVE-2019-10160 | A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6… | In your normal cycle | 9.8 critical | 5.2% | 2019-06-07 |
| CVE-2020-10611 | Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to execute arbitrary code due to t… | In your normal cycle | 9.8 critical | 5.2% | 2020-04-15 |
| CVE-2026-27174 | MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in… | In your normal cycle | 9.8 critical | 5.2% | 2026-02-18 |
| CVE-2013-2093 | Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary c… | In your normal cycle | 9.8 critical | 5.2% | 2019-11-20 |
| CVE-2017-3223 | Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web interface that may be vulnerabl… | In your normal cycle | 9.8 critical | 5.2% | 2018-07-24 |
| CVE-2020-15798 | A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panel… | In your normal cycle | 9.8 critical | 5.2% | 2021-02-09 |
| CVE-2020-28036 | wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post. | In your normal cycle | 9.8 critical | 5.2% | 2020-11-02 |
| CVE-2018-11800 | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts r… | In your normal cycle | 9.8 critical | 5.2% | 2019-06-11 |
| CVE-2018-11801 | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related… | In your normal cycle | 9.8 critical | 5.2% | 2019-06-11 |
| CVE-2021-43113 | iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghosts… | In your normal cycle | 9.8 critical | 5.2% | 2021-12-15 |
| CVE-2020-12279 | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short n… | In your normal cycle | 9.8 critical | 5.2% | 2020-04-27 |
| CVE-2022-1161 | An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems.… | In your normal cycle | 10.0 critical | 5.2% | 2022-04-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt