CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,908 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,882 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-13774 | An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain re… | In your normal cycle | 9.9 critical | 5% | 2020-11-12 |
| CVE-2020-24341 | An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The TCP input data processing function in pico_tcp.c does not validate the length of… | In your normal cycle | 9.1 critical | 5% | 2020-12-11 |
| CVE-2020-10886 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 router… | In your normal cycle | 9.8 critical | 5% | 2020-03-25 |
| CVE-2023-1020 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJ… | In your normal cycle | 9.8 critical | 4.9% | 2023-04-24 |
| CVE-2014-9912 | The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does no… | In your normal cycle | 9.8 critical | 4.9% | 2017-01-04 |
| CVE-2021-42665 | An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an atta… | In your normal cycle | 9.8 critical | 4.9% | 2021-11-05 |
| CVE-2022-25438 | Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function. | In your normal cycle | 9.8 critical | 4.9% | 2022-03-18 |
| CVE-2022-25441 | Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter in the SetIPTVCfg function. | In your normal cycle | 9.8 critical | 4.9% | 2022-03-18 |
| CVE-2020-9585 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security miti… | In your normal cycle | 9.8 critical | 4.9% | 2020-06-26 |
| CVE-2016-7399 | scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attack… | In your normal cycle | 9.8 critical | 4.9% | 2017-01-04 |
| CVE-2020-27263 | KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Roc… | In your normal cycle | 9.1 critical | 4.9% | 2021-01-14 |
| CVE-2020-27267 | KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Roc… | In your normal cycle | 9.1 critical | 4.9% | 2021-01-14 |
| CVE-2016-3957 | The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which might… | In your normal cycle | 9.8 critical | 4.9% | 2018-02-06 |
| CVE-2024-24759 | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side… | In your normal cycle | 9.3 critical | 4.9% | 2024-09-05 |
| CVE-2020-6962 | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X,… | In your normal cycle | 10.0 critical | 4.9% | 2020-01-24 |
| CVE-2020-27846 | A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from thi… | In your normal cycle | 9.8 critical | 4.9% | 2020-12-21 |
| CVE-2017-15940 | The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x… | In your normal cycle | 9.8 critical | 4.9% | 2017-12-11 |
| CVE-2017-14948 | Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code… | In your normal cycle | 9.8 critical | 4.9% | 2019-10-14 |
| CVE-2018-19514 | In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. Exploitation requires authenti… | In your normal cycle | 9.8 critical | 4.9% | 2019-03-21 |
| CVE-2026-79697 | A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WI… | In your normal cycle | 9.9 critical | 4.9% | 2026-09-07 |
| CVE-2018-3746 | The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's… | In your normal cycle | 9.8 critical | 4.9% | 2018-06-01 |
| CVE-2019-18289 | A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could t… | In your normal cycle | 9.8 critical | 4.9% | 2019-12-12 |
| CVE-2019-18293 | A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could t… | In your normal cycle | 9.8 critical | 4.9% | 2019-12-12 |
| CVE-2019-18295 | A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could t… | In your normal cycle | 9.8 critical | 4.9% | 2019-12-12 |
| CVE-2019-18296 | A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could t… | In your normal cycle | 9.8 critical | 4.9% | 2019-12-12 |
| CVE-2015-8710 | The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds he… | In your normal cycle | 9.8 critical | 4.9% | 2016-04-11 |
| CVE-2019-10842 | Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker… | In your normal cycle | 9.8 critical | 4.9% | 2019-04-04 |
| CVE-2017-9807 | An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of "plugin/controllers/models/config.py" pe… | In your normal cycle | 9.8 critical | 4.9% | 2017-06-22 |
| CVE-2016-4608 | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchO… | In your normal cycle | 9.8 critical | 4.9% | 2016-07-22 |
| CVE-2017-14429 | The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows u… | In your normal cycle | 9.8 critical | 4.9% | 2017-09-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt