CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,534 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,944 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-6638 | A stack-based buffer overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. This occurs in a function call in which th… | In your normal cycle | 9.8 critical | 3.9% | 2018-02-28 |
| CVE-2018-6640 | A Heap Overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can modify the next pointer of a linked li… | In your normal cycle | 9.8 critical | 3.9% | 2018-02-28 |
| CVE-2016-9835 | Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launc… | In your normal cycle | 9.8 critical | 3.9% | 2016-12-05 |
| CVE-2018-14813 | Fuji Electric V-Server 4.0.3.0 and prior, A heap-based buffer overflow vulnerability has been identified, which may allow remote code execution. | In your normal cycle | 9.8 critical | 3.9% | 2018-09-26 |
| CVE-2018-14823 | Fuji Electric V-Server 4.0.3.0 and prior, A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution. | In your normal cycle | 9.8 critical | 3.9% | 2018-09-26 |
| CVE-2019-11063 | A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the sam… | In your normal cycle | 10.0 critical | 3.9% | 2019-08-29 |
| CVE-2021-42783 | Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows an unauthenticated attacker to… | In your normal cycle | 9.8 critical | 3.9% | 2021-11-23 |
| CVE-2017-15293 | Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain att… | In your normal cycle | 9.8 critical | 3.9% | 2017-10-16 |
| CVE-2018-19857 | The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies… | In your normal cycle | 9.1 critical | 3.9% | 2018-12-05 |
| CVE-2017-10151 | Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affect… | In your normal cycle | 10.0 critical | 3.9% | 2017-10-30 |
| CVE-2018-14358 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response wit… | In your normal cycle | 9.8 critical | 3.9% | 2018-07-17 |
| CVE-2017-9148 | The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably p… | In your normal cycle | 9.8 critical | 3.9% | 2017-05-29 |
| CVE-2017-8380 | Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote attackers to have unspecified impact via unknown vectors. | In your normal cycle | 9.8 critical | 3.9% | 2017-08-28 |
| CVE-2023-0037 | The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL… | In your normal cycle | 9.8 critical | 3.9% | 2023-03-13 |
| CVE-2016-5568 | Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability via… | In your normal cycle | 9.6 critical | 3.9% | 2016-10-25 |
| CVE-2026-84434 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file functi… | In your normal cycle | 9.8 critical | 3.9% | 2026-09-19 |
| CVE-2016-4336 | An exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted Bzip2 d… | In your normal cycle | 9.8 critical | 3.9% | 2017-01-06 |
| CVE-2019-3954 | Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafte… | In your normal cycle | 9.8 critical | 3.9% | 2019-06-19 |
| CVE-2016-7996 | Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colo… | In your normal cycle | 9.8 critical | 3.9% | 2017-01-18 |
| CVE-2019-11319 | An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware in hnap, which leads to remote… | In your normal cycle | 9.8 critical | 3.9% | 2019-04-18 |
| CVE-2019-11322 | An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in hnap, which leads to remote c… | In your normal cycle | 9.8 critical | 3.9% | 2019-04-18 |
| CVE-2026-15826 | The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This… | In your normal cycle | 9.8 critical | 3.9% | 2026-08-15 |
| CVE-2022-3634 | The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV in… | In your normal cycle | 9.8 critical | 3.9% | 2022-11-21 |
| CVE-2016-7790 | Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the website through… | In your normal cycle | 9.8 critical | 3.9% | 2017-01-12 |
| CVE-2016-7791 | Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil 'exploit.tar.gz' file to t… | In your normal cycle | 9.8 critical | 3.9% | 2017-01-12 |
| CVE-2020-3375 | A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. Th… | In your normal cycle | 9.8 critical | 3.9% | 2020-07-31 |
| CVE-2020-28910 | Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, w… | In your normal cycle | 9.8 critical | 3.9% | 2021-05-24 |
| CVE-2023-36619 | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users. | In your normal cycle | 9.8 critical | 3.9% | 2023-10-04 |
| CVE-2015-5041 | The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote att… | In your normal cycle | 9.1 critical | 3.9% | 2016-06-06 |
| CVE-2016-6501 | JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP… | In your normal cycle | 9.8 critical | 3.9% | 2016-12-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt