CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,429 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,936 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-1473 | Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP ob… | In your normal cycle | 9.8 critical | 4% | 2016-09-02 |
| CVE-2026-76904 | GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6,… | In your normal cycle | 9.8 critical | 4% | 2026-08-21 |
| CVE-2023-34034 | Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFl… | In your normal cycle | 9.1 critical | 4% | 2023-07-19 |
| CVE-2022-29321 | D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan. | In your normal cycle | 9.8 critical | 4% | 2022-05-10 |
| CVE-2022-29323 | D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment. | In your normal cycle | 9.8 critical | 4% | 2022-05-10 |
| CVE-2022-29324 | D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd. | In your normal cycle | 9.8 critical | 4% | 2022-05-10 |
| CVE-2020-10108 | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the firs… | In your normal cycle | 9.8 critical | 4% | 2020-03-12 |
| CVE-2018-0651 | Buffer overflow in the license management function of YOKOGAWA products (iDefine for ProSafe-RS R1.16.3 and earlier, STARDOM VDS R7.50 and earlier, ST… | In your normal cycle | 9.8 critical | 4% | 2019-01-09 |
| CVE-2026-14483 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.… | In your normal cycle | 9.8 critical | 4% | 2026-07-31 |
| CVE-2022-44290 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php. | In your normal cycle | 9.8 critical | 4% | 2022-12-02 |
| CVE-2022-44291 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php. | In your normal cycle | 9.8 critical | 4% | 2022-12-02 |
| CVE-2018-12410 | The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of… | In your normal cycle | 9.8 critical | 4% | 2018-10-10 |
| CVE-2019-8275 | UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being accessed by… | In your normal cycle | 9.8 critical | 4% | 2019-03-08 |
| CVE-2021-44880 | D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerabilit… | In your normal cycle | 9.8 critical | 4% | 2022-02-04 |
| CVE-2014-2025 | Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x… | In your normal cycle | 9.8 critical | 4% | 2020-01-31 |
| CVE-2019-0736 | A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker w… | In your normal cycle | 9.8 critical | 4% | 2019-08-14 |
| CVE-2019-1205 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successful… | In your normal cycle | 9.8 critical | 4% | 2019-08-14 |
| CVE-2019-12146 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abu… | In your normal cycle | 9.1 critical | 4% | 2019-06-11 |
| CVE-2026-18612 | A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the… | In your normal cycle | 9.8 critical | 4% | 2026-08-03 |
| CVE-2015-8659 | The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug. | In your normal cycle | 10.0 critical | 4% | 2016-01-12 |
| CVE-2021-1139 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary… | In your normal cycle | 9.8 critical | 4% | 2021-01-20 |
| CVE-2021-1141 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary… | In your normal cycle | 9.8 critical | 4% | 2021-01-20 |
| CVE-2016-5270 | Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4… | In your normal cycle | 9.8 critical | 4% | 2016-09-22 |
| CVE-2022-40475 | TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi. | In your normal cycle | 9.8 critical | 4% | 2022-09-29 |
| CVE-2021-28122 | A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a cra… | In your normal cycle | 9.8 critical | 4% | 2021-03-10 |
| CVE-2015-6792 | The MIDI subsystem in Google Chrome before 47.0.2526.106 does not properly handle the sending of data, which allows remote attackers to execute arbitr… | In your normal cycle | 9.8 critical | 4% | 2015-12-24 |
| CVE-2018-1164 | This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3… | In your normal cycle | 9.8 critical | 4% | 2018-02-21 |
| CVE-2015-9471 | The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload. | In your normal cycle | 9.8 critical | 4% | 2019-10-10 |
| CVE-2016-4119 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4% | 2016-08-26 |
| CVE-2018-4991 | Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability. Successful… | In your normal cycle | 9.8 critical | 4% | 2018-05-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt