CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,659 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,954 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-18869 | EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecm… | In your normal cycle | 9.8 critical | 3.7% | 2018-10-31 |
| CVE-2026-86299 | A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the… | In your normal cycle | 9.9 critical | 3.7% | 2026-09-07 |
| CVE-2019-16915 | An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.… | In your normal cycle | 9.8 critical | 3.7% | 2019-09-26 |
| CVE-2021-22667 | BB-ESWGP506-2SFP-T versions 1.01.09 and prior is vulnerable due to the use of hard-coded credentials, which may allow an attacker to gain unauthorized… | In your normal cycle | 9.8 critical | 3.7% | 2021-02-24 |
| CVE-2021-37388 | A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver a… | In your normal cycle | 9.8 critical | 3.7% | 2021-08-06 |
| CVE-2018-7440 | An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot root… | In your normal cycle | 9.8 critical | 3.7% | 2018-02-23 |
| CVE-2020-24203 | Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.… | In your normal cycle | 9.8 critical | 3.7% | 2020-08-27 |
| CVE-2020-3763 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… | In your normal cycle | 9.8 critical | 3.7% | 2020-02-13 |
| CVE-2014-9826 | ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files. | In your normal cycle | 9.8 critical | 3.7% | 2017-03-30 |
| CVE-2022-24437 | The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also suppor… | In your normal cycle | 9.8 critical | 3.7% | 2022-05-01 |
| CVE-2016-1037 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 3.7% | 2016-05-11 |
| CVE-2019-9227 | An issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary code. A BG_SITE_NAME parameter… | In your normal cycle | 9.8 critical | 3.7% | 2019-02-28 |
| CVE-2013-4454 | WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities | In your normal cycle | 9.1 critical | 3.7% | 2020-02-18 |
| CVE-2013-10040 | ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. Th… | In your normal cycle | 9.8 critical | 3.7% | 2025-07-31 |
| CVE-2018-17916 | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker c… | In your normal cycle | 9.8 critical | 3.7% | 2018-11-02 |
| CVE-2019-16730 | processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary syste… | In your normal cycle | 9.8 critical | 3.7% | 2019-12-13 |
| CVE-2016-9941 | Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application… | In your normal cycle | 9.8 critical | 3.7% | 2016-12-31 |
| CVE-2019-3989 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input… | In your normal cycle | 9.8 critical | 3.7% | 2019-12-11 |
| CVE-2022-30510 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59. | In your normal cycle | 9.8 critical | 3.7% | 2022-06-02 |
| CVE-2017-9097 | In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 device… | In your normal cycle | 9.1 critical | 3.7% | 2017-06-16 |
| CVE-2021-20020 | A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root. | In your normal cycle | 9.8 critical | 3.7% | 2021-04-10 |
| CVE-2020-15490 | An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exist in CGI scripts, leading to… | In your normal cycle | 9.8 critical | 3.7% | 2020-07-01 |
| CVE-2021-2064 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected i… | In your normal cycle | 9.8 critical | 3.7% | 2021-01-20 |
| CVE-2021-2108 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected i… | In your normal cycle | 9.8 critical | 3.7% | 2021-01-20 |
| CVE-2021-28294 | Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code… | In your normal cycle | 9.8 critical | 3.7% | 2021-03-16 |
| CVE-2021-24376 | The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" fe… | In your normal cycle | 9.8 critical | 3.7% | 2021-06-21 |
| CVE-2018-16975 | An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php exten… | In your normal cycle | 9.8 critical | 3.7% | 2018-09-12 |
| CVE-2018-20718 | In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a prefere… | In your normal cycle | 9.8 critical | 3.7% | 2019-01-15 |
| CVE-2018-19240 | Buffer overflow in network.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devices allows at… | In your normal cycle | 9.8 critical | 3.7% | 2018-12-20 |
| CVE-2021-1264 | A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. Th… | In your normal cycle | 9.6 critical | 3.7% | 2021-01-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt