CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,696 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,955 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-7241 | Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the co… | In your normal cycle | 9.8 critical | 3.7% | 2018-04-18 |
| CVE-2020-6779 | Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthentic… | In your normal cycle | 10.0 critical | 3.7% | 2021-01-26 |
| CVE-2020-16257 | Winston 1.5.4 devices are vulnerable to command injection via the API. | In your normal cycle | 9.8 critical | 3.7% | 2020-10-28 |
| CVE-2022-21178 | An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-c… | In your normal cycle | 9.8 critical | 3.7% | 2022-08-05 |
| CVE-2022-22140 | An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-craf… | In your normal cycle | 9.8 critical | 3.7% | 2022-08-05 |
| CVE-2022-32573 | A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP r… | In your normal cycle | 9.9 critical | 3.7% | 2022-12-15 |
| CVE-2020-27583 | IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execu… | In your normal cycle | 9.8 critical | 3.7% | 2021-01-26 |
| CVE-2020-10887 | This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not… | In your normal cycle | 9.8 critical | 3.7% | 2020-03-25 |
| CVE-2020-12006 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privileg… | In your normal cycle | 9.8 critical | 3.7% | 2020-05-08 |
| CVE-2019-17408 | parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be… | In your normal cycle | 9.8 critical | 3.7% | 2019-10-14 |
| CVE-2018-16402 | libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecifi… | In your normal cycle | 9.8 critical | 3.7% | 2018-09-03 |
| CVE-2022-1440 | Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input,… | In your normal cycle | 9.8 critical | 3.7% | 2022-04-22 |
| CVE-2020-15487 | Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protected/models/Ticket.php file. By… | In your normal cycle | 9.8 critical | 3.7% | 2020-09-30 |
| CVE-2020-5312 | libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow. | In your normal cycle | 9.8 critical | 3.7% | 2020-01-03 |
| CVE-2020-24199 | Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote cod… | In your normal cycle | 9.8 critical | 3.7% | 2020-09-09 |
| CVE-2023-39638 | D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cg… | In your normal cycle | 9.8 critical | 3.7% | 2023-09-14 |
| CVE-2023-45158 | An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not th… | In your normal cycle | 9.8 critical | 3.7% | 2023-10-16 |
| CVE-2015-5684 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly… | In your normal cycle | 9.8 critical | 3.7% | 2020-03-27 |
| CVE-2017-2989 | Adobe Campaign versions Build 8770 and earlier have an input validation bypass that could be exploited to read, write, or delete data from the Campaig… | In your normal cycle | 9.1 critical | 3.7% | 2017-04-12 |
| CVE-2018-11462 | A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4.… | In your normal cycle | 9.8 critical | 3.7% | 2018-12-12 |
| CVE-2016-6374 | Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, aka… | In your normal cycle | 9.8 critical | 3.7% | 2016-09-22 |
| CVE-2024-20720 | Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command… | In your normal cycle | 9.1 critical | 3.7% | 2024-02-15 |
| CVE-2018-3972 | An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (v… | In your normal cycle | 9.8 critical | 3.7% | 2018-09-26 |
| CVE-2020-12460 | OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte… | In your normal cycle | 9.8 critical | 3.7% | 2020-07-27 |
| CVE-2020-8955 | irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and app… | In your normal cycle | 9.8 critical | 3.7% | 2020-02-12 |
| CVE-2021-20658 | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vect… | In your normal cycle | 9.8 critical | 3.7% | 2021-02-24 |
| CVE-2021-20042 | An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerabil… | In your normal cycle | 9.8 critical | 3.7% | 2021-12-08 |
| CVE-2017-3632 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: CDE Calendar). Supported versions that are affected are 10… | In your normal cycle | 9.8 critical | 3.7% | 2017-08-08 |
| CVE-2018-17148 | An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios… | In your normal cycle | 9.8 critical | 3.7% | 2019-06-19 |
| CVE-2023-40749 | PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php. | In your normal cycle | 9.8 critical | 3.7% | 2023-08-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt