CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,557 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,944 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-19595 | PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/… | In your normal cycle | 9.8 critical | 3.9% | 2018-11-27 |
| CVE-2018-10105 | tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2). | In your normal cycle | 9.8 critical | 3.9% | 2019-10-03 |
| CVE-2020-7631 | diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument. | In your normal cycle | 9.8 critical | 3.9% | 2020-04-06 |
| CVE-2018-16461 | A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options… | In your normal cycle | 9.8 critical | 3.9% | 2018-10-30 |
| CVE-2019-15102 | An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication m… | In your normal cycle | 9.8 critical | 3.9% | 2019-09-06 |
| CVE-2023-29199 | There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass… | In your normal cycle | 9.8 critical | 3.9% | 2023-04-14 |
| CVE-2020-12284 | cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a… | In your normal cycle | 9.8 critical | 3.9% | 2020-04-28 |
| CVE-2021-31737 | emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php. | In your normal cycle | 9.8 critical | 3.9% | 2021-05-06 |
| CVE-2019-8186 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | In your normal cycle | 9.8 critical | 3.8% | 2019-10-17 |
| CVE-2023-30150 | PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php. | In your normal cycle | 9.8 critical | 3.8% | 2023-06-14 |
| CVE-2020-6008 | LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution | In your normal cycle | 9.8 critical | 3.8% | 2020-03-31 |
| CVE-2022-31003 | Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `r… | In your normal cycle | 9.1 critical | 3.8% | 2022-05-31 |
| CVE-2026-28409 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA a… | In your normal cycle | 10.0 critical | 3.8% | 2026-02-27 |
| CVE-2017-7318 | Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to… | In your normal cycle | 9.8 critical | 3.8% | 2017-03-30 |
| CVE-2020-28270 | Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead… | In your normal cycle | 9.8 critical | 3.8% | 2020-11-12 |
| CVE-2016-6206 | Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or execute arbitrary code via a craft… | In your normal cycle | 9.8 critical | 3.8% | 2017-03-24 |
| CVE-2021-31891 | A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or e… | In your normal cycle | 10.0 critical | 3.8% | 2021-09-14 |
| CVE-2016-5256 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory… | In your normal cycle | 9.8 critical | 3.8% | 2016-09-22 |
| CVE-2022-44808 | A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary… | In your normal cycle | 9.8 critical | 3.8% | 2022-11-22 |
| CVE-2017-8818 | curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possib… | In your normal cycle | 9.8 critical | 3.8% | 2017-11-29 |
| CVE-2018-11499 | A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 that could be leveraged to cause… | In your normal cycle | 9.8 critical | 3.8% | 2018-05-26 |
| CVE-2019-6980 | Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component. | In your normal cycle | 9.8 critical | 3.8% | 2019-05-29 |
| CVE-2020-12441 | Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ a… | In your normal cycle | 9.8 critical | 3.8% | 2020-08-06 |
| CVE-2020-29600 | In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/a… | In your normal cycle | 9.8 critical | 3.8% | 2020-12-07 |
| CVE-2022-29325 | D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addurlfilter parameter in /goform/websURLFilter. | In your normal cycle | 9.8 critical | 3.8% | 2022-05-10 |
| CVE-2022-29326 | D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parameter in /goform/websHostFilter. | In your normal cycle | 9.8 critical | 3.8% | 2022-05-10 |
| CVE-2022-29327 | D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the urladd parameter in /goform/websURLFilterAddDel. | In your normal cycle | 9.8 critical | 3.8% | 2022-05-10 |
| CVE-2018-8850 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not validate input properly, allowing an attacker to craft the in… | In your normal cycle | 9.8 critical | 3.8% | 2018-09-26 |
| CVE-2017-15398 | A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to gain code execution via a mal… | In your normal cycle | 9.8 critical | 3.8% | 2018-08-28 |
| CVE-2022-27268 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the c… | In your normal cycle | 9.8 critical | 3.8% | 2022-04-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt