CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,041 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,891 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-10699 | avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a w… | In your normal cycle | 9.8 critical | 4.5% | 2017-06-30 |
| CVE-2021-44882 | D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability all… | In your normal cycle | 9.8 critical | 4.5% | 2022-02-04 |
| CVE-2019-17670 | WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relati… | In your normal cycle | 9.8 critical | 4.5% | 2019-10-17 |
| CVE-2018-5468 | Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain unauthorized… | In your normal cycle | 9.8 critical | 4.5% | 2018-03-26 |
| CVE-2018-5472 | Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to gain unaut… | In your normal cycle | 9.8 critical | 4.5% | 2018-03-26 |
| CVE-2019-9186 | In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when th… | In your normal cycle | 9.8 critical | 4.5% | 2019-07-03 |
| CVE-2021-29300 | The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands on… | In your normal cycle | 9.8 critical | 4.5% | 2021-05-24 |
| CVE-2026-3301 | A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /… | In your normal cycle | 9.8 critical | 4.5% | 2026-02-27 |
| CVE-2025-62521 | ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's… | In your normal cycle | 10.0 critical | 4.5% | 2025-12-17 |
| CVE-2025-42880 | Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function… | In your normal cycle | 9.9 critical | 4.5% | 2025-12-09 |
| CVE-2018-9866 | A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance'… | In your normal cycle | 9.8 critical | 4.5% | 2018-08-03 |
| CVE-2018-10730 | All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection. | In your normal cycle | 9.1 critical | 4.5% | 2018-05-17 |
| CVE-2016-4519 | Stack-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.30 allows remote attackers to execute arbitrary code via a crafted filename fi… | In your normal cycle | 9.8 critical | 4.5% | 2016-06-25 |
| CVE-2020-29214 | SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admi… | In your normal cycle | 9.8 critical | 4.5% | 2021-06-15 |
| CVE-2019-25141 | The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability… | In your normal cycle | 9.8 critical | 4.5% | 2023-06-07 |
| CVE-2016-1986 | HP Continuous Delivery Automation (CDA) 1.30 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to th… | In your normal cycle | 9.8 critical | 4.5% | 2016-02-12 |
| CVE-2026-29014 | MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary c… | In your normal cycle | 9.8 critical | 4.5% | 2026-04-01 |
| CVE-2019-7667 | Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable name, and an attacker can use bru… | In your normal cycle | 9.8 critical | 4.5% | 2019-07-01 |
| CVE-2017-12180 | xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or poss… | In your normal cycle | 9.8 critical | 4.5% | 2018-01-24 |
| CVE-2017-12183 | xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly exe… | In your normal cycle | 9.8 critical | 4.5% | 2018-01-24 |
| CVE-2017-13019 | The PGM parser in tcpdump before 4.9.2 has a buffer over-read in print-pgm.c:pgm_print(). | In your normal cycle | 9.8 critical | 4.5% | 2017-09-14 |
| CVE-2017-13038 | The PPP parser in tcpdump before 4.9.2 has a buffer over-read in print-ppp.c:handle_mlppp(). | In your normal cycle | 9.8 critical | 4.5% | 2017-09-14 |
| CVE-2017-17406 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not… | In your normal cycle | 9.8 critical | 4.5% | 2018-01-23 |
| CVE-2019-1974 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Di… | In your normal cycle | 9.8 critical | 4.5% | 2019-08-21 |
| CVE-2020-9895 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Saf… | In your normal cycle | 9.8 critical | 4.5% | 2020-10-16 |
| CVE-2021-4380 | The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_par… | In your normal cycle | 9.8 critical | 4.5% | 2023-06-07 |
| CVE-2021-40521 | Airangel HSMX Gateway devices through 5.2.04 allow Remote Code Execution. | In your normal cycle | 9.8 critical | 4.5% | 2021-11-10 |
| CVE-2016-9482 | Code generated by PHP FormMail Generator may allow a remote unauthenticated user to bypass authentication in the to access the administrator panel by… | In your normal cycle | 9.8 critical | 4.5% | 2018-07-13 |
| CVE-2016-5114 | sapi/fpm/fpm/fpm_log.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 misinterprets the semantics of the snprintf return value, which… | In your normal cycle | 9.1 critical | 4.5% | 2016-08-07 |
| CVE-2018-20060 | urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in hos… | In your normal cycle | 9.8 critical | 4.5% | 2018-12-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt