CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,373 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,927 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-5257 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow r… | In your normal cycle | 9.8 critical | 4.2% | 2016-09-22 |
| CVE-2010-4478 | OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attacker… | In your normal cycle | 9.8 critical | 4.2% | 2010-12-06 |
| CVE-2022-26612 | In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR e… | In your normal cycle | 9.8 critical | 4.2% | 2022-04-07 |
| CVE-2020-14516 | In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing al… | In your normal cycle | 10.0 critical | 4.2% | 2021-03-18 |
| CVE-2020-28282 | Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution. | In your normal cycle | 9.8 critical | 4.2% | 2020-12-29 |
| CVE-2020-29474 | EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection quer… | In your normal cycle | 9.8 critical | 4.2% | 2020-12-24 |
| CVE-2019-1109 | A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An a… | In your normal cycle | 9.1 critical | 4.2% | 2019-07-15 |
| CVE-2019-10061 | utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user inp… | In your normal cycle | 9.8 critical | 4.2% | 2019-03-26 |
| CVE-2020-3357 | A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers co… | In your normal cycle | 9.8 critical | 4.2% | 2020-07-16 |
| CVE-2021-1289 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allo… | In your normal cycle | 9.8 critical | 4.2% | 2021-02-04 |
| CVE-2021-1290 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allo… | In your normal cycle | 9.8 critical | 4.2% | 2021-02-04 |
| CVE-2021-1291 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allo… | In your normal cycle | 9.8 critical | 4.2% | 2021-02-04 |
| CVE-2021-1295 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allo… | In your normal cycle | 9.8 critical | 4.2% | 2021-02-04 |
| CVE-2017-1000219 | npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user | In your normal cycle | 9.8 critical | 4.2% | 2017-11-17 |
| CVE-2023-0600 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing u… | In your normal cycle | 9.8 critical | 4.2% | 2023-05-15 |
| CVE-2017-12181 | xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possibl… | In your normal cycle | 9.8 critical | 4.2% | 2018-01-24 |
| CVE-2017-12182 | xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possibl… | In your normal cycle | 9.8 critical | 4.2% | 2018-01-24 |
| CVE-2017-16608 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not… | In your normal cycle | 9.8 critical | 4.2% | 2018-01-23 |
| CVE-2018-3601 | A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication on… | In your normal cycle | 9.8 critical | 4.2% | 2018-02-09 |
| CVE-2020-24647 | A remote accessmgrservlet classname input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s)… | In your normal cycle | 9.8 critical | 4.2% | 2020-10-19 |
| CVE-2020-24649 | A remote bytemessageresource transformentity" input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC)… | In your normal cycle | 9.8 critical | 4.2% | 2020-10-19 |
| CVE-2023-34751 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit. | In your normal cycle | 9.8 critical | 4.2% | 2023-06-14 |
| CVE-2023-34753 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit. | In your normal cycle | 9.8 critical | 4.2% | 2023-06-14 |
| CVE-2023-34755 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit. | In your normal cycle | 9.8 critical | 4.2% | 2023-06-14 |
| CVE-2023-34756 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=ed… | In your normal cycle | 9.8 critical | 4.2% | 2023-06-14 |
| CVE-2020-36244 | The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute ar… | In your normal cycle | 9.8 critical | 4.2% | 2021-02-10 |
| CVE-2021-45039 | Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an u… | In your normal cycle | 9.8 critical | 4.2% | 2023-05-31 |
| CVE-2019-4202 | IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrar… | In your normal cycle | 10.0 critical | 4.2% | 2019-04-15 |
| CVE-2016-6520 | Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows remote attackers to have unspecified impact via vectors related to pixel… | In your normal cycle | 9.1 critical | 4.2% | 2016-12-13 |
| CVE-2026-22252 | LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validat… | In your normal cycle | 9.1 critical | 4.2% | 2026-01-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt