CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,899 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,882 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-0742 | Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of ty… | In your normal cycle | 9.1 critical | 5% | 2022-03-18 |
| CVE-2016-5280 | Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45… | In your normal cycle | 9.8 critical | 5% | 2016-09-22 |
| CVE-2016-5281 | Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows rem… | In your normal cycle | 9.8 critical | 5% | 2016-09-22 |
| CVE-2023-34939 | Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx… | In your normal cycle | 9.8 critical | 5% | 2023-06-22 |
| CVE-2019-12585 | Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php. | In your normal cycle | 9.8 critical | 5% | 2019-06-03 |
| CVE-2011-3188 | The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identi… | In your normal cycle | 9.1 critical | 5% | 2012-05-24 |
| CVE-2018-17200 | The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpServic… | In your normal cycle | 9.8 critical | 5% | 2019-09-11 |
| CVE-2019-16309 | FlameCMS 3.3.5 has SQL injection in account/login.php via accountName. | In your normal cycle | 9.8 critical | 5% | 2019-09-14 |
| CVE-2016-6293 | The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that… | In your normal cycle | 9.8 critical | 5% | 2016-07-25 |
| CVE-2024-3136 | The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' paramete… | In your normal cycle | 9.8 critical | 5% | 2024-04-09 |
| CVE-2014-6120 | IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0… | In your normal cycle | 9.8 critical | 5% | 2018-04-12 |
| CVE-2019-6557 | Several buffer overflow vulnerabilities have been identified in Moxa IKS and EDS, which may allow remote code execution. | In your normal cycle | 9.8 critical | 5% | 2019-03-05 |
| CVE-2018-0268 | A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attack… | In your normal cycle | 10.0 critical | 5% | 2018-05-17 |
| CVE-2024-34832 | Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g an… | In your normal cycle | 9.8 critical | 5% | 2024-06-06 |
| CVE-2014-5401 | Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenti… | In your normal cycle | 9.8 critical | 5% | 2019-03-26 |
| CVE-2016-4609 | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchO… | In your normal cycle | 9.8 critical | 5% | 2016-07-22 |
| CVE-2020-9423 | LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. Logica… | In your normal cycle | 9.8 critical | 5% | 2020-03-18 |
| CVE-2022-4117 | The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthent… | In your normal cycle | 9.8 critical | 5% | 2022-12-26 |
| CVE-2019-10744 | Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying prope… | In your normal cycle | 9.1 critical | 5% | 2019-07-26 |
| CVE-2012-1622 | Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors. | In your normal cycle | 9.8 critical | 5% | 2017-10-26 |
| CVE-2020-3740 | Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | In your normal cycle | 9.8 critical | 5% | 2020-02-13 |
| CVE-2018-6968 | The VMware AirWatch Agent for Android prior to 8.2 and AirWatch Agent for Windows Mobile prior to 6.5.2 contain a remote code execution vulnerability… | In your normal cycle | 10.0 critical | 5% | 2018-06-11 |
| CVE-2024-29275 | SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information… | In your normal cycle | 9.8 critical | 5% | 2024-03-22 |
| CVE-2025-36846 | An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated us… | In your normal cycle | 9.8 critical | 5% | 2025-07-21 |
| CVE-2026-30623 | LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP serve… | In your normal cycle | 9.8 critical | 5% | 2026-07-15 |
| CVE-2016-10144 | coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check. | In your normal cycle | 9.8 critical | 5% | 2017-03-24 |
| CVE-2018-10611 | Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauth… | In your normal cycle | 9.8 critical | 5% | 2018-06-04 |
| CVE-2015-9272 | The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers… | In your normal cycle | 9.8 critical | 5% | 2018-10-05 |
| CVE-2020-10018 | WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free… | In your normal cycle | 9.8 critical | 5% | 2020-03-02 |
| CVE-2014-6440 | VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service. | In your normal cycle | 9.8 critical | 5% | 2017-03-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt