CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,534 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,944 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-9019 | SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to… | In your normal cycle | 9.8 critical | 3.9% | 2018-05-22 |
| CVE-2022-26842 | A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master commit 3f7c03… | In your normal cycle | 9.6 critical | 3.9% | 2022-08-22 |
| CVE-2018-1115 | postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same A… | In your normal cycle | 9.1 critical | 3.9% | 2018-05-10 |
| CVE-2019-7610 | Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.securit… | In your normal cycle | 9.0 critical | 3.9% | 2019-03-25 |
| CVE-2014-0121 | The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter. | In your normal cycle | 9.8 critical | 3.9% | 2017-12-29 |
| CVE-2020-11722 | Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .c… | In your normal cycle | 9.8 critical | 3.9% | 2020-04-12 |
| CVE-2017-14062 | Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibl… | In your normal cycle | 9.8 critical | 3.9% | 2017-08-31 |
| CVE-2015-1801 | The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a denial of service (memory corr… | In your normal cycle | 9.8 critical | 3.9% | 2017-08-24 |
| CVE-2015-8389 | PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite rec… | In your normal cycle | 9.8 critical | 3.9% | 2015-12-02 |
| CVE-2018-12914 | A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directo… | In your normal cycle | 9.8 critical | 3.9% | 2018-06-27 |
| CVE-2021-27466 | A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifie… | In your normal cycle | 10.0 critical | 3.9% | 2022-03-23 |
| CVE-2018-7058 | Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerabil… | In your normal cycle | 9.8 critical | 3.9% | 2018-08-06 |
| CVE-2021-21888 | An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU)… | In your normal cycle | 9.1 critical | 3.9% | 2021-12-22 |
| CVE-2019-19212 | Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen). | In your normal cycle | 9.8 critical | 3.9% | 2020-03-16 |
| CVE-2017-5390 | The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allo… | In your normal cycle | 9.8 critical | 3.9% | 2018-06-11 |
| CVE-2026-47668 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code executi… | In your normal cycle | 10.0 critical | 3.9% | 2026-07-23 |
| CVE-2018-19007 | In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration panel) is vulnerable to an OS sy… | In your normal cycle | 9.8 critical | 3.9% | 2018-12-14 |
| CVE-2020-8171 | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0… | In your normal cycle | 9.8 critical | 3.9% | 2020-05-26 |
| CVE-2016-1662 | extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback execution once the Garbage Collection callback has s… | In your normal cycle | 9.8 critical | 3.9% | 2016-05-14 |
| CVE-2019-1010298 | Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The compone… | In your normal cycle | 9.8 critical | 3.9% | 2019-07-15 |
| CVE-2017-17107 | Zivif PR115-204-P-RS V2.3.4.2103 web cameras contain a hard-coded cat1029 password for the root user. The SONIX operating system's setup renders this… | In your normal cycle | 9.8 critical | 3.9% | 2017-12-19 |
| CVE-2017-1000082 | systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privil… | In your normal cycle | 9.8 critical | 3.9% | 2017-07-07 |
| CVE-2026-42796 | Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins quer… | In your normal cycle | 9.8 critical | 3.9% | 2026-05-04 |
| CVE-2021-45840 | It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted input… | In your normal cycle | 9.8 critical | 3.9% | 2022-04-25 |
| CVE-2025-66209 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated… | In your normal cycle | 9.9 critical | 3.9% | 2025-12-23 |
| CVE-2009-3616 | Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on… | In your normal cycle | 9.9 critical | 3.9% | 2009-10-23 |
| CVE-2013-20002 | Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/them… | In your normal cycle | 9.8 critical | 3.9% | 2021-06-17 |
| CVE-2019-15800 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(),… | In your normal cycle | 9.8 critical | 3.9% | 2019-11-14 |
| CVE-2019-19334 | In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "ident… | In your normal cycle | 9.8 critical | 3.9% | 2019-12-06 |
| CVE-2023-3197 | The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.… | In your normal cycle | 9.8 critical | 3.9% | 2023-06-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt