CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,286 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,914 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-36719 | The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in vers… | In your normal cycle | 9.8 critical | 4.3% | 2023-06-07 |
| CVE-2017-12186 | xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibly… | In your normal cycle | 9.8 critical | 4.3% | 2018-01-24 |
| CVE-2019-12523 | An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through t… | In your normal cycle | 9.1 critical | 4.3% | 2019-11-26 |
| CVE-2018-11629 | Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device throu… | In your normal cycle | 9.8 critical | 4.3% | 2018-06-02 |
| CVE-2018-11681 | Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNE… | In your normal cycle | 9.8 critical | 4.3% | 2018-06-02 |
| CVE-2018-11682 | Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products usi… | In your normal cycle | 9.8 critical | 4.3% | 2018-06-02 |
| CVE-2022-40222 | An OS command injection vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-craft… | In your normal cycle | 9.8 critical | 4.3% | 2023-01-26 |
| CVE-2022-45709 | IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule parameters in… | In your normal cycle | 9.8 critical | 4.3% | 2022-12-23 |
| CVE-2022-45717 | IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartitio… | In your normal cycle | 9.8 critical | 4.3% | 2022-12-23 |
| CVE-2019-5402 | A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. | In your normal cycle | 9.4 critical | 4.3% | 2019-08-09 |
| CVE-2022-23219 | The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on t… | In your normal cycle | 9.8 critical | 4.3% | 2022-01-14 |
| CVE-2020-29472 | EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious… | In your normal cycle | 9.8 critical | 4.3% | 2020-12-24 |
| CVE-2008-2108 | The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a porti… | In your normal cycle | 9.8 critical | 4.3% | 2008-05-07 |
| CVE-2018-14324 | The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This al… | In your normal cycle | 9.8 critical | 4.3% | 2018-07-16 |
| CVE-2017-1000169 | QuickerBB version <= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead to the complete takeover of t… | In your normal cycle | 9.8 critical | 4.3% | 2017-11-17 |
| CVE-2019-11365 | An issue was discovered in atftpd in atftp 0.7.1. A remote attacker may send a crafted packet triggering a stack-based buffer overflow due to an insec… | In your normal cycle | 9.8 critical | 4.3% | 2019-04-20 |
| CVE-2008-2374 | src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields i… | In your normal cycle | 9.8 critical | 4.3% | 2008-07-07 |
| CVE-2019-19495 | The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via… | In your normal cycle | 9.8 critical | 4.3% | 2020-01-08 |
| CVE-2012-0828 | Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of… | In your normal cycle | 9.8 critical | 4.3% | 2020-02-21 |
| CVE-2015-8914 | The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protecti… | In your normal cycle | 9.1 critical | 4.3% | 2016-06-17 |
| CVE-2015-0781 | Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers t… | In your normal cycle | 9.8 critical | 4.3% | 2017-08-09 |
| CVE-2020-23653 | An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/cont… | In your normal cycle | 9.8 critical | 4.3% | 2021-01-13 |
| CVE-2019-19317 | lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a deni… | In your normal cycle | 9.8 critical | 4.3% | 2019-12-05 |
| CVE-2019-18643 | Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism… | In your normal cycle | 9.8 critical | 4.3% | 2021-01-07 |
| CVE-2019-10651 | An issue was discovered in the Core Server in Ivanti Endpoint Manager (EPM) 2017.3 before SU7 and 2018.x before 2018.3 SU3, with remote code execution… | In your normal cycle | 9.8 critical | 4.3% | 2019-07-11 |
| CVE-2019-8069 | Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful expl… | In your normal cycle | 9.8 critical | 4.3% | 2019-09-12 |
| CVE-2014-1508 | The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before… | In your normal cycle | 9.1 critical | 4.3% | 2014-03-19 |
| CVE-2022-45808 | SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. | In your normal cycle | 9.9 critical | 4.3% | 2023-01-26 |
| CVE-2020-8137 | Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker. | In your normal cycle | 9.8 critical | 4.3% | 2020-03-20 |
| CVE-2019-5397 | A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | In your normal cycle | 9.4 critical | 4.3% | 2019-08-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt