CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,041 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,891 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-10251 | A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and… | In your normal cycle | 9.8 critical | 4.5% | 2018-05-04 |
| CVE-2016-6912 | Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecifie… | In your normal cycle | 9.8 critical | 4.5% | 2017-01-26 |
| CVE-2022-1986 | OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9. | In your normal cycle | 9.8 critical | 4.5% | 2022-06-09 |
| CVE-2019-14313 | A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability woul… | In your normal cycle | 9.8 critical | 4.5% | 2019-07-30 |
| CVE-2017-17484 | The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for… | In your normal cycle | 9.8 critical | 4.5% | 2017-12-10 |
| CVE-2026-77806 | SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code… | In your normal cycle | 9.8 critical | 4.5% | 2026-08-21 |
| CVE-2021-27362 | The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might… | In your normal cycle | 9.8 critical | 4.5% | 2021-02-17 |
| CVE-2014-9984 | nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup… | In your normal cycle | 9.8 critical | 4.5% | 2017-06-12 |
| CVE-2020-29127 | An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web br… | In your normal cycle | 9.8 critical | 4.5% | 2020-11-30 |
| CVE-2017-16618 | An exploitable vulnerability exists in the YAML loading functionality of util.py in OwlMixin before 2.0.0a12. A "Load YAML" string or file (aka load_y… | In your normal cycle | 9.8 critical | 4.5% | 2017-11-08 |
| CVE-2017-16763 | An exploitable vulnerability exists in the YAML parsing functionality in config.py in Confire 0.2.0. Due to the user-specific configuration being load… | In your normal cycle | 9.8 critical | 4.5% | 2017-11-10 |
| CVE-2020-3198 | Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Co… | In your normal cycle | 9.8 critical | 4.5% | 2020-06-03 |
| CVE-2018-12976 | In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a dir… | In your normal cycle | 9.8 critical | 4.5% | 2018-07-05 |
| CVE-2019-15751 | An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with a… | In your normal cycle | 9.8 critical | 4.5% | 2019-10-07 |
| CVE-2024-39781 | Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafte… | In your normal cycle | 9.1 critical | 4.5% | 2025-01-14 |
| CVE-2024-39783 | Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafte… | In your normal cycle | 9.1 critical | 4.5% | 2025-01-14 |
| CVE-2014-2302 | The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by in… | In your normal cycle | 9.8 critical | 4.5% | 2018-07-19 |
| CVE-2024-11613 | The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all version… | In your normal cycle | 9.8 critical | 4.5% | 2025-01-08 |
| CVE-2017-5954 | An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to ac… | In your normal cycle | 9.8 critical | 4.5% | 2017-02-10 |
| CVE-2019-14698 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. In a CGI program running under the HTTPD web server, a buff… | In your normal cycle | 9.8 critical | 4.5% | 2019-08-06 |
| CVE-2019-14708 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the action parameter leads to remote c… | In your normal cycle | 9.8 critical | 4.5% | 2019-08-06 |
| CVE-2018-18861 | Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command. | In your normal cycle | 9.8 critical | 4.5% | 2018-11-20 |
| CVE-2017-13719 | The Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various functionalities of the camera… | In your normal cycle | 9.8 critical | 4.5% | 2019-07-03 |
| CVE-2016-7942 | The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, whi… | In your normal cycle | 9.8 critical | 4.5% | 2016-12-13 |
| CVE-2016-7943 | The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigge… | In your normal cycle | 9.8 critical | 4.5% | 2016-12-13 |
| CVE-2017-3834 | A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express Software could allow an unauth… | In your normal cycle | 9.8 critical | 4.5% | 2017-04-06 |
| CVE-2019-6824 | A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthenticated, remote attacker to ex… | In your normal cycle | 9.8 critical | 4.5% | 2019-07-15 |
| CVE-2022-35866 | This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authenticati… | In your normal cycle | 9.8 critical | 4.5% | 2022-08-03 |
| CVE-2016-2000 | HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafte… | In your normal cycle | 9.8 critical | 4.5% | 2016-04-05 |
| CVE-2016-2003 | HPE P9000 Command View Advanced Edition Software (CVAE) 7.x and 8.x before 8.4.0-00 and XP7 CVAE 7.x and 8.x before 8.4.0-00 allow remote attackers to… | In your normal cycle | 9.8 critical | 4.5% | 2016-04-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt