CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,707 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,958 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-13569 | A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of thi… | In your normal cycle | 9.8 critical | 3.7% | 2019-07-19 |
| CVE-2018-17068 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functio… | In your normal cycle | 9.8 critical | 3.7% | 2018-09-15 |
| CVE-2019-19948 | In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c. | In your normal cycle | 9.8 critical | 3.7% | 2019-12-24 |
| CVE-2021-35978 | An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges.… | In your normal cycle | 9.8 critical | 3.7% | 2021-12-10 |
| CVE-2016-9540 | tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width. Reported as MSVR 35103, aka "cpStri… | In your normal cycle | 9.8 critical | 3.7% | 2016-11-22 |
| CVE-2026-42589 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON… | In your normal cycle | 9.8 critical | 3.7% | 2026-05-14 |
| CVE-2016-9538 | tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow. Reported as MSVR 351… | In your normal cycle | 9.8 critical | 3.7% | 2016-11-22 |
| CVE-2023-43374 | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php. | In your normal cycle | 9.8 critical | 3.7% | 2023-09-20 |
| CVE-2019-16303 | A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness… | In your normal cycle | 9.8 critical | 3.7% | 2019-09-14 |
| CVE-2019-20216 | D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi(… | In your normal cycle | 9.8 critical | 3.7% | 2020-01-29 |
| CVE-2019-18182 | pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsig… | In your normal cycle | 9.8 critical | 3.7% | 2020-02-24 |
| CVE-2019-18183 | pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsign… | In your normal cycle | 9.8 critical | 3.7% | 2020-02-24 |
| CVE-2013-3073 | A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34. | In your normal cycle | 9.8 critical | 3.7% | 2019-11-14 |
| CVE-2017-10918 | Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access,… | In your normal cycle | 10.0 critical | 3.7% | 2017-07-05 |
| CVE-2016-6798 | In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string,… | In your normal cycle | 9.8 critical | 3.7% | 2017-07-19 |
| CVE-2018-20033 | A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote at… | In your normal cycle | 9.8 critical | 3.7% | 2019-02-25 |
| CVE-2013-2259 | Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview | In your normal cycle | 9.8 critical | 3.7% | 2019-11-04 |
| CVE-2018-14362 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with me… | In your normal cycle | 9.8 critical | 3.7% | 2018-07-17 |
| CVE-2023-2163 | Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write… | In your normal cycle | 10.0 critical | 3.7% | 2023-09-20 |
| CVE-2017-3206 | The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external entity references (XXEs) from… | In your normal cycle | 9.8 critical | 3.7% | 2018-06-11 |
| CVE-2022-21196 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does… | In your normal cycle | 10.0 critical | 3.7% | 2022-02-18 |
| CVE-2017-7614 | elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" und… | In your normal cycle | 9.8 critical | 3.7% | 2017-04-09 |
| CVE-2019-11210 | The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketpla… | In your normal cycle | 10.0 critical | 3.7% | 2019-09-18 |
| CVE-2018-17787 | On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is… | In your normal cycle | 9.8 critical | 3.7% | 2018-10-02 |
| CVE-2016-6548 | The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated session token with the URL. An… | In your normal cycle | 9.8 critical | 3.7% | 2018-07-13 |
| CVE-2020-21994 | AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an… | In your normal cycle | 9.8 critical | 3.7% | 2021-04-28 |
| CVE-2020-23083 | Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to… | In your normal cycle | 9.8 critical | 3.7% | 2021-05-03 |
| CVE-2020-12443 | BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the… | In your normal cycle | 9.8 critical | 3.7% | 2020-04-29 |
| CVE-2022-50794 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers c… | In your normal cycle | 9.8 critical | 3.7% | 2025-12-30 |
| CVE-2019-5597 | In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in the… | In your normal cycle | 9.1 critical | 3.7% | 2019-05-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt