CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,011 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,888 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-5644 | Buffer overflow vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version "05.65.00.BD"… | In your normal cycle | 9.8 critical | 4.5% | 2020-11-06 |
| CVE-2021-40903 | A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a… | In your normal cycle | 9.8 critical | 4.5% | 2022-06-17 |
| CVE-2022-32270 | In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code E… | In your normal cycle | 9.8 critical | 4.5% | 2022-06-03 |
| CVE-2022-3982 | The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated use… | In your normal cycle | 9.8 critical | 4.5% | 2022-12-12 |
| CVE-2026-34234 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is… | In your normal cycle | 10.0 critical | 4.5% | 2026-05-19 |
| CVE-2019-18189 | A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker… | In your normal cycle | 9.8 critical | 4.5% | 2019-10-28 |
| CVE-2020-7995 | The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts. | In your normal cycle | 9.8 critical | 4.5% | 2020-01-26 |
| CVE-2016-6147 | An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified… | In your normal cycle | 9.8 critical | 4.5% | 2016-08-05 |
| CVE-2018-6476 | In SUPERAntiSpyware Professional Trial 6.0.1254, the SASKUTIL.SYS driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating… | In your normal cycle | 9.8 critical | 4.5% | 2018-01-31 |
| CVE-2018-12699 | finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified ot… | In your normal cycle | 9.8 critical | 4.5% | 2018-06-23 |
| CVE-2020-13388 | An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configurat… | In your normal cycle | 9.8 critical | 4.5% | 2020-05-22 |
| CVE-2022-1509 | Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execu… | In your normal cycle | 9.9 critical | 4.5% | 2022-04-28 |
| CVE-2019-20041 | wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input san… | In your normal cycle | 9.8 critical | 4.5% | 2019-12-27 |
| CVE-2024-39911 | 1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been… | In your normal cycle | 10.0 critical | 4.5% | 2024-07-18 |
| CVE-2020-16608 | Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true). | In your normal cycle | 9.6 critical | 4.5% | 2020-12-10 |
| CVE-2020-4207 | IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when hand… | In your normal cycle | 9.8 critical | 4.5% | 2020-01-28 |
| CVE-2016-5407 | The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access… | In your normal cycle | 9.8 critical | 4.5% | 2016-12-13 |
| CVE-2015-5224 | The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attac… | In your normal cycle | 9.8 critical | 4.5% | 2017-08-23 |
| CVE-2018-5241 | Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6.5, 6.6, and 6.7 are susceptible to a SAML authentication bypass vulnerability. The p… | In your normal cycle | 9.8 critical | 4.5% | 2018-05-29 |
| CVE-2021-33527 | In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORIT… | In your normal cycle | 9.8 critical | 4.5% | 2021-08-02 |
| CVE-2015-8949 | Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call t… | In your normal cycle | 9.8 critical | 4.5% | 2016-08-19 |
| CVE-2021-1294 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allo… | In your normal cycle | 9.8 critical | 4.5% | 2021-02-04 |
| CVE-2019-5081 | An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmware version 03.01.07(… | In your normal cycle | 9.8 critical | 4.5% | 2019-12-18 |
| CVE-2017-4997 | EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code execution vulnerability that could potentially be expl… | In your normal cycle | 9.8 critical | 4.5% | 2017-06-29 |
| CVE-2018-1309 | Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fi… | In your normal cycle | 9.8 critical | 4.5% | 2018-05-23 |
| CVE-2017-8116 | The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary… | In your normal cycle | 9.8 critical | 4.5% | 2017-07-03 |
| CVE-2016-5086 | Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks. | In your normal cycle | 9.8 critical | 4.5% | 2016-10-05 |
| CVE-2016-5686 | Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a c… | In your normal cycle | 9.8 critical | 4.5% | 2016-10-05 |
| CVE-2018-14010 | OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15, and R3D… | In your normal cycle | 9.8 critical | 4.5% | 2018-07-15 |
| CVE-2018-14060 | OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D before 2.26.4 devices allows an at… | In your normal cycle | 9.8 critical | 4.5% | 2018-07-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt