CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,415 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,932 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-3065 | The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to b… | In your normal cycle | 9.1 critical | 4.1% | 2016-04-11 |
| CVE-2014-1409 | MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated… | In your normal cycle | 9.1 critical | 4% | 2020-01-08 |
| CVE-2018-19290 | In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command injection attack against the… | In your normal cycle | 9.8 critical | 4% | 2018-11-30 |
| CVE-2019-13224 | A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service,… | In your normal cycle | 9.8 critical | 4% | 2019-07-10 |
| CVE-2019-9099 | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB318… | In your normal cycle | 9.8 critical | 4% | 2020-03-11 |
| CVE-2018-11052 | Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnera… | In your normal cycle | 9.8 critical | 4% | 2018-07-03 |
| CVE-2019-7162 | An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthenticated person to retrieve intern… | In your normal cycle | 9.1 critical | 4% | 2019-12-31 |
| CVE-2020-26772 | Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the 'AjaxRun()' function. | In your normal cycle | 9.8 critical | 4% | 2021-09-08 |
| CVE-2020-28273 | Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code ex… | In your normal cycle | 9.8 critical | 4% | 2020-12-02 |
| CVE-2022-27139 | An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. N… | In your normal cycle | 9.8 critical | 4% | 2022-04-12 |
| CVE-2015-7687 | Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vect… | In your normal cycle | 9.8 critical | 4% | 2017-10-16 |
| CVE-2019-1010306 | Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted reques… | In your normal cycle | 9.8 critical | 4% | 2019-07-15 |
| CVE-2017-17479 | In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bound… | In your normal cycle | 9.8 critical | 4% | 2017-12-08 |
| CVE-2016-5276 | Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x be… | In your normal cycle | 9.8 critical | 4% | 2016-09-22 |
| CVE-2016-3541 | Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and… | In your normal cycle | 9.1 critical | 4% | 2016-07-21 |
| CVE-2016-3543 | Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and… | In your normal cycle | 9.1 critical | 4% | 2016-07-21 |
| CVE-2017-2787 | A buffer overflows exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the v… | In your normal cycle | 9.0 critical | 4% | 2017-03-10 |
| CVE-2021-32157 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. | In your normal cycle | 9.6 critical | 4% | 2022-04-11 |
| CVE-2021-26703 | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI. | In your normal cycle | 9.8 critical | 4% | 2021-03-01 |
| CVE-2018-14551 | The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory corruption. | In your normal cycle | 9.8 critical | 4% | 2018-07-23 |
| CVE-2018-20732 | SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant. | In your normal cycle | 9.8 critical | 4% | 2019-01-17 |
| CVE-2018-18498 | A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the… | In your normal cycle | 9.8 critical | 4% | 2019-02-28 |
| CVE-2019-19330 | The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa),… | In your normal cycle | 9.8 critical | 4% | 2019-11-27 |
| CVE-2019-11929 | Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote… | In your normal cycle | 9.8 critical | 4% | 2019-10-02 |
| CVE-2020-20951 | In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files. | In your normal cycle | 9.8 critical | 4% | 2021-05-18 |
| CVE-2016-9832 | PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbitr… | In your normal cycle | 9.9 critical | 4% | 2016-12-10 |
| CVE-2021-33191 | From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. Thi… | In your normal cycle | 9.8 critical | 4% | 2021-08-24 |
| CVE-2016-7447 | Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via un… | In your normal cycle | 9.8 critical | 4% | 2017-02-06 |
| CVE-2018-15394 | A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to bypas… | In your normal cycle | 9.8 critical | 4% | 2018-11-08 |
| CVE-2017-2126 | WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and access th… | In your normal cycle | 9.8 critical | 4% | 2017-07-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt