CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,999 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,886 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-28888 | Spryker Commerce OS 1.4.2 allows Remote Command Execution. | In your normal cycle | 9.8 critical | 4.7% | 2022-07-13 |
| CVE-2020-6109 | An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted… | In your normal cycle | 9.8 critical | 4.7% | 2020-06-08 |
| CVE-2016-6582 | The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to im… | In your normal cycle | 9.1 critical | 4.7% | 2017-01-23 |
| CVE-2019-5619 | AASync.com AASync version 2.2.1.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow. | In your normal cycle | 9.8 critical | 4.7% | 2020-04-29 |
| CVE-2016-0686 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integri… | In your normal cycle | 9.6 critical | 4.7% | 2016-04-21 |
| CVE-2016-0687 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integri… | In your normal cycle | 9.6 critical | 4.7% | 2016-04-21 |
| CVE-2021-43741 | CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading… | In your normal cycle | 9.8 critical | 4.7% | 2022-04-13 |
| CVE-2023-27847 | SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xip… | In your normal cycle | 9.8 critical | 4.7% | 2023-03-27 |
| CVE-2020-13556 | An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A sp… | In your normal cycle | 9.8 critical | 4.7% | 2020-12-11 |
| CVE-2021-46227 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function proxy_client.asp. This vulnerabili… | In your normal cycle | 9.8 critical | 4.7% | 2022-02-04 |
| CVE-2017-11147 | In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP int… | In your normal cycle | 9.1 critical | 4.7% | 2017-07-10 |
| CVE-2016-6082 | IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition. An attacker coul… | In your normal cycle | 10.0 critical | 4.7% | 2017-02-01 |
| CVE-2014-5009 | Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008. | In your normal cycle | 9.8 critical | 4.7% | 2017-03-31 |
| CVE-2016-6496 | The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attr… | In your normal cycle | 9.8 critical | 4.7% | 2016-12-09 |
| CVE-2018-1000300 | curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that… | In your normal cycle | 9.8 critical | 4.7% | 2018-05-24 |
| CVE-2018-15506 | In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remot… | In your normal cycle | 9.8 critical | 4.7% | 2019-06-19 |
| CVE-2015-8098 | F5 BIG-IP APM 11.4.1 before 11.4.1 HF9, 11.5.x before 11.5.3, and 11.6.0 before 11.6.0 HF4 allow remote attackers to cause a denial of service or exec… | In your normal cycle | 9.8 critical | 4.7% | 2016-01-12 |
| CVE-2017-5461 | Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remo… | In your normal cycle | 9.8 critical | 4.7% | 2017-05-11 |
| CVE-2022-28491 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter.… | In your normal cycle | 9.8 critical | 4.7% | 2023-03-23 |
| CVE-2016-5873 | Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable c… | In your normal cycle | 9.8 critical | 4.7% | 2017-01-23 |
| CVE-2017-15548 | An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integ… | In your normal cycle | 9.8 critical | 4.7% | 2018-01-05 |
| CVE-2019-3464 | Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restric… | In your normal cycle | 9.8 critical | 4.7% | 2019-02-06 |
| CVE-2020-37153 | ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management i… | In your normal cycle | 9.8 critical | 4.7% | 2026-02-11 |
| CVE-2016-2141 | It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use t… | In your normal cycle | 9.8 critical | 4.7% | 2016-06-30 |
| CVE-2018-15350 | Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the router. | In your normal cycle | 9.8 critical | 4.7% | 2018-08-17 |
| CVE-2019-11991 | HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4… | In your normal cycle | 9.8 critical | 4.7% | 2019-07-09 |
| CVE-2017-5810 | A remote sql injection vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found. | In your normal cycle | 9.8 critical | 4.7% | 2018-02-15 |
| CVE-2022-24126 | A buffer overflow in the NRSessionSearchResult parser in Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allows remote attackers to execut… | In your normal cycle | 9.8 critical | 4.7% | 2022-03-20 |
| CVE-2018-16428 | In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference. | In your normal cycle | 9.8 critical | 4.7% | 2018-09-04 |
| CVE-2022-31767 | IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted reques… | In your normal cycle | 9.8 critical | 4.7% | 2022-06-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt