CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,932 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-5666 | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows remote attac… | In your normal cycle | 9.8 critical | 4.2% | 2016-08-03 |
| CVE-2022-30422 | Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate para… | In your normal cycle | 9.8 critical | 4.2% | 2022-06-17 |
| CVE-2019-13598 | LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_348… | In your normal cycle | 9.8 critical | 4.2% | 2019-07-14 |
| CVE-2017-6714 | A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arbi… | In your normal cycle | 9.8 critical | 4.2% | 2017-07-06 |
| CVE-2018-5384 | Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection. If successfully exploited th… | In your normal cycle | 9.8 critical | 4.2% | 2018-07-24 |
| CVE-2017-7676 | Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in un… | In your normal cycle | 9.8 critical | 4.2% | 2017-06-14 |
| CVE-2018-10620 | AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packe… | In your normal cycle | 9.8 critical | 4.2% | 2018-07-19 |
| CVE-2021-25913 | Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote… | In your normal cycle | 9.8 critical | 4.2% | 2021-02-08 |
| CVE-2026-56413 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default an… | In your normal cycle | 10.0 critical | 4.2% | 2026-06-30 |
| CVE-2016-4326 | The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data… | In your normal cycle | 9.8 critical | 4.2% | 2016-06-10 |
| CVE-2020-11920 | An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in the HOST/IP section of the NFS… | In your normal cycle | 9.8 critical | 4.2% | 2021-02-08 |
| CVE-2018-8826 | ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N6… | In your normal cycle | 9.8 critical | 4.2% | 2018-04-20 |
| CVE-2025-31651 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it… | In your normal cycle | 9.8 critical | 4.2% | 2025-04-28 |
| CVE-2019-6203 | A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privile… | In your normal cycle | 9.8 critical | 4.2% | 2020-04-17 |
| CVE-2018-12910 | The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname. | In your normal cycle | 9.8 critical | 4.2% | 2018-07-05 |
| CVE-2019-11680 | KonaKart 8.9.0.0 is vulnerable to Remote Code Execution by uploading a web shell as a product category image. | In your normal cycle | 9.8 critical | 4.2% | 2019-05-13 |
| CVE-2019-19634 | class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht… | In your normal cycle | 9.8 critical | 4.2% | 2019-12-17 |
| CVE-2015-7554 | The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly h… | In your normal cycle | 9.8 critical | 4.2% | 2016-01-08 |
| CVE-2018-18461 | The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via P… | In your normal cycle | 9.8 critical | 4.2% | 2018-10-18 |
| CVE-2018-6537 | A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code b… | In your normal cycle | 9.8 critical | 4.2% | 2018-02-02 |
| CVE-2016-0917 | The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638),… | In your normal cycle | 9.8 critical | 4.2% | 2016-09-21 |
| CVE-2021-3342 | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI. | In your normal cycle | 9.8 critical | 4.2% | 2021-03-01 |
| CVE-2021-1292 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allo… | In your normal cycle | 9.8 critical | 4.2% | 2021-02-04 |
| CVE-2016-7856 | Adobe DNG Converter versions 9.7 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code… | In your normal cycle | 9.8 critical | 4.2% | 2016-12-15 |
| CVE-2018-2913 | Vulnerability in the Oracle GoldenGate component of Oracle GoldenGate (subcomponent: Monitoring Manager). Supported versions that are affected are 12.… | In your normal cycle | 10.0 critical | 4.2% | 2018-10-17 |
| CVE-2018-8710 | A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the s… | In your normal cycle | 9.8 critical | 4.2% | 2018-03-14 |
| CVE-2020-8600 | Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulat… | In your normal cycle | 9.8 critical | 4.2% | 2020-03-18 |
| CVE-2022-22012 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | In your normal cycle | 9.8 critical | 4.2% | 2022-05-10 |
| CVE-2023-26482 | Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which… | In your normal cycle | 9.0 critical | 4.2% | 2023-03-30 |
| CVE-2020-23833 | Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on th… | In your normal cycle | 9.8 critical | 4.2% | 2020-09-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt