CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,932 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-5539 | The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ..\/ to bypass t… | In your normal cycle | 9.1 critical | 4.2% | 2017-01-23 |
| CVE-2018-20784 | In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in… | In your normal cycle | 9.8 critical | 4.2% | 2019-02-22 |
| CVE-2015-5626 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and ea… | In your normal cycle | 9.8 critical | 4.2% | 2020-02-05 |
| CVE-2015-5627 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and ea… | In your normal cycle | 9.8 critical | 4.2% | 2020-02-05 |
| CVE-2019-3705 | Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 an… | In your normal cycle | 9.8 critical | 4.2% | 2019-04-26 |
| CVE-2020-10208 | Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B a… | In your normal cycle | 9.9 critical | 4.2% | 2020-12-30 |
| CVE-2021-36782 | A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Proje… | In your normal cycle | 9.9 critical | 4.2% | 2022-09-07 |
| CVE-2015-8866 | ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader… | In your normal cycle | 9.6 critical | 4.2% | 2016-05-22 |
| CVE-2020-22079 | Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code v… | In your normal cycle | 9.8 critical | 4.2% | 2021-10-29 |
| CVE-2016-2029 | HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a differ… | In your normal cycle | 9.1 critical | 4.2% | 2016-06-08 |
| CVE-2017-12184 | xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly e… | In your normal cycle | 9.8 critical | 4.2% | 2018-01-24 |
| CVE-2017-12185 | xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or po… | In your normal cycle | 9.8 critical | 4.2% | 2018-01-24 |
| CVE-2017-12176 | xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to… | In your normal cycle | 9.8 critical | 4.2% | 2018-01-24 |
| CVE-2020-28269 | Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code exe… | In your normal cycle | 9.8 critical | 4.2% | 2020-11-12 |
| CVE-2016-8352 | An issue was discovered in Schneider Electric ConneXium firewalls TCSEFEC23F3F20 all versions, TCSEFEC23F3F21 all versions, TCSEFEC23FCF20 all version… | In your normal cycle | 10.0 critical | 4.2% | 2017-02-13 |
| CVE-2017-11588 | On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V0… | In your normal cycle | 9.8 critical | 4.2% | 2017-07-24 |
| CVE-2018-9318 | The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a remote atta… | In your normal cycle | 9.8 critical | 4.2% | 2018-05-31 |
| CVE-2023-33863 | SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to 0xffffffffffffffff… | In your normal cycle | 9.8 critical | 4.2% | 2023-06-07 |
| CVE-2023-33864 | StreamReader::ReadFromExternal in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. It uses uint32_t(m_BufferSize-m_I… | In your normal cycle | 9.8 critical | 4.2% | 2023-06-07 |
| CVE-2024-4898 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization che… | In your normal cycle | 9.8 critical | 4.2% | 2024-06-12 |
| CVE-2024-39764 | Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specia… | In your normal cycle | 9.1 critical | 4.2% | 2025-01-14 |
| CVE-2016-6139 | SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Security Note 2203591. | In your normal cycle | 9.8 critical | 4.2% | 2016-08-05 |
| CVE-2015-2874 | Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105… | In your normal cycle | 9.8 critical | 4.2% | 2015-12-31 |
| CVE-2020-28024 | Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtp_ungetc wa… | In your normal cycle | 9.8 critical | 4.2% | 2021-05-06 |
| CVE-2024-3605 | The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API end… | In your normal cycle | 10.0 critical | 4.2% | 2024-06-20 |
| CVE-2026-26213 | thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulnerability in the WiFi captive po… | In your normal cycle | 9.8 critical | 4.1% | 2026-03-26 |
| CVE-2022-25247 | Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port witho… | In your normal cycle | 9.8 critical | 4.1% | 2022-03-16 |
| CVE-2022-30055 | Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution. | In your normal cycle | 9.8 critical | 4.1% | 2022-05-16 |
| CVE-2018-17063 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fun… | In your normal cycle | 9.8 critical | 4.1% | 2018-09-15 |
| CVE-2013-4521 | RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods ca… | In your normal cycle | 9.8 critical | 4.1% | 2020-02-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt