CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,932 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-6809 | NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system… | In your normal cycle | 9.8 critical | 4.1% | 2018-03-06 |
| CVE-2022-21306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.1.3.0.0… | In your normal cycle | 9.8 critical | 4.1% | 2022-01-19 |
| CVE-2016-9427 | Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and… | In your normal cycle | 9.8 critical | 4.1% | 2016-12-12 |
| CVE-2017-10932 | All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the ap… | In your normal cycle | 9.8 critical | 4.1% | 2017-09-28 |
| CVE-2026-26190 | Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, wh… | In your normal cycle | 9.8 critical | 4.1% | 2026-02-13 |
| CVE-2018-7539 | On Appear TV XC5000 and XC5100 devices with firmware 3.26.217, it is possible to read OS files with a specially crafted HTTP request (such as GET /../… | In your normal cycle | 9.8 critical | 4.1% | 2018-04-17 |
| CVE-2018-6376 | In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall me… | In your normal cycle | 9.8 critical | 4.1% | 2018-01-30 |
| CVE-2018-9838 | The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where mars… | In your normal cycle | 9.8 critical | 4.1% | 2018-04-06 |
| CVE-2021-44847 | A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper leng… | In your normal cycle | 9.8 critical | 4.1% | 2021-12-13 |
| CVE-2016-15057 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum.… | In your normal cycle | 9.9 critical | 4.1% | 2026-01-26 |
| CVE-2017-7785 | A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially ex… | In your normal cycle | 9.8 critical | 4.1% | 2018-06-11 |
| CVE-2017-7786 | A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. T… | In your normal cycle | 9.8 critical | 4.1% | 2018-06-11 |
| CVE-2024-6205 | The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a W… | In your normal cycle | 9.8 critical | 4.1% | 2024-07-19 |
| CVE-2008-7109 | The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to the… | In your normal cycle | 9.8 critical | 4.1% | 2009-08-28 |
| CVE-2018-1000178 | A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStreamPeer::processMessage(const QByteArray &msg) datast… | In your normal cycle | 9.8 critical | 4.1% | 2018-05-08 |
| CVE-2018-14359 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data. | In your normal cycle | 9.8 critical | 4.1% | 2018-07-17 |
| CVE-2018-14816 | Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that have been identified, which may allow an attacker t… | In your normal cycle | 9.8 critical | 4.1% | 2018-10-23 |
| CVE-2012-10020 | The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify.php file in versions u… | In your normal cycle | 9.8 critical | 4.1% | 2025-07-22 |
| CVE-2014-5008 | Snoopy allows remote attackers to execute arbitrary commands. | In your normal cycle | 9.8 critical | 4.1% | 2017-03-31 |
| CVE-2018-19488 | The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php… | In your normal cycle | 9.8 critical | 4.1% | 2019-03-21 |
| CVE-2020-25952 | SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute… | In your normal cycle | 9.8 critical | 4.1% | 2020-11-16 |
| CVE-2019-19840 | A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauth… | In your normal cycle | 9.8 critical | 4.1% | 2020-01-22 |
| CVE-2018-17198 | Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SA… | In your normal cycle | 9.8 critical | 4.1% | 2019-05-28 |
| CVE-2016-4861 | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attac… | In your normal cycle | 9.8 critical | 4.1% | 2017-02-17 |
| CVE-2017-1000378 | The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() t… | In your normal cycle | 9.8 critical | 4.1% | 2017-06-19 |
| CVE-2013-4267 | Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power… | In your normal cycle | 9.8 critical | 4.1% | 2020-02-11 |
| CVE-2019-9121 | An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote at… | In your normal cycle | 9.8 critical | 4.1% | 2019-03-07 |
| CVE-2018-19486 | Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involvi… | In your normal cycle | 9.8 critical | 4.1% | 2018-11-23 |
| CVE-2021-34622 | A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it… | In your normal cycle | 9.8 critical | 4.1% | 2021-07-07 |
| CVE-2019-11933 | A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow remote attack… | In your normal cycle | 9.8 critical | 4.1% | 2019-10-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt