CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,999 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,886 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-15255 | A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of the component R7websSsecurityHan… | In your normal cycle | 9.8 critical | 4.7% | 2025-12-30 |
| CVE-2018-1000134 | UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue… | In your normal cycle | 9.8 critical | 4.7% | 2018-03-16 |
| CVE-2026-58123 | Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell c… | In your normal cycle | 9.8 critical | 4.6% | 2026-07-09 |
| CVE-2014-1532 | Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x… | In your normal cycle | 9.8 critical | 4.6% | 2014-04-30 |
| CVE-2021-42128 | An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise… | In your normal cycle | 9.8 critical | 4.6% | 2021-12-07 |
| CVE-2020-3258 | Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Co… | In your normal cycle | 9.8 critical | 4.6% | 2020-06-03 |
| CVE-2025-47577 | Unrestricted Upload of File with Dangerous Type vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Upload a Web… | In your normal cycle | 10.0 critical | 4.6% | 2025-05-19 |
| CVE-2017-2520 | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | In your normal cycle | 9.8 critical | 4.6% | 2017-05-22 |
| CVE-2017-13050 | The RPKI-Router parser in tcpdump before 4.9.2 has a buffer over-read in print-rpki-rtr.c:rpki_rtr_pdu_print(). | In your normal cycle | 9.8 critical | 4.6% | 2017-09-14 |
| CVE-2022-29472 | An OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, Inc. iota All-In-One Security Ki… | In your normal cycle | 9.8 critical | 4.6% | 2022-10-25 |
| CVE-2021-44881 | D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerabi… | In your normal cycle | 9.8 critical | 4.6% | 2022-02-04 |
| CVE-2019-7266 | Linear eMerge 50P/5000P devices allow Authentication Bypass. | In your normal cycle | 9.8 critical | 4.6% | 2019-07-02 |
| CVE-2018-7084 | A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary… | In your normal cycle | 9.8 critical | 4.6% | 2019-05-10 |
| CVE-2021-40113 | Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Ter… | In your normal cycle | 10.0 critical | 4.6% | 2021-11-04 |
| CVE-2017-10788 | The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly h… | In your normal cycle | 9.8 critical | 4.6% | 2017-07-01 |
| CVE-2017-18269 | An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.2… | In your normal cycle | 9.8 critical | 4.6% | 2018-05-18 |
| CVE-2019-17267 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransaction… | In your normal cycle | 9.8 critical | 4.6% | 2019-10-07 |
| CVE-2019-10121 | eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authorization checks. An attacke… | In your normal cycle | 9.8 critical | 4.6% | 2019-07-10 |
| CVE-2024-27115 | A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can… | In your normal cycle | 9.8 critical | 4.6% | 2024-09-11 |
| CVE-2017-5459 | A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Fi… | In your normal cycle | 9.8 critical | 4.6% | 2018-06-11 |
| CVE-2019-10774 | php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. | In your normal cycle | 9.8 critical | 4.6% | 2019-12-30 |
| CVE-2015-8608 | The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly exe… | In your normal cycle | 9.8 critical | 4.6% | 2017-02-07 |
| CVE-2019-14230 | An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count aja… | In your normal cycle | 9.8 critical | 4.6% | 2019-07-21 |
| CVE-2019-14231 | An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_re… | In your normal cycle | 9.8 critical | 4.6% | 2019-07-21 |
| CVE-2021-35049 | Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could… | In your normal cycle | 9.9 critical | 4.6% | 2021-06-25 |
| CVE-2021-26754 | wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection. | In your normal cycle | 9.8 critical | 4.6% | 2021-02-08 |
| CVE-2020-9546 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shade… | In your normal cycle | 9.8 critical | 4.6% | 2020-03-02 |
| CVE-2018-19275 | The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attackers… | In your normal cycle | 9.8 critical | 4.6% | 2019-04-02 |
| CVE-2018-9284 | authentication.cgi on D-Link DIR-868L devices with Singapore StarHub firmware before v1.21SHCb03 allows remote attackers to execute arbitrary code. | In your normal cycle | 9.8 critical | 4.6% | 2018-04-04 |
| CVE-2020-9493 | A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution. | In your normal cycle | 9.8 critical | 4.6% | 2021-06-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt