CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,707 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,958 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-5740 | The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP re… | In your normal cycle | 9.8 critical | 3.7% | 2017-10-18 |
| CVE-2020-8964 | TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003,… | In your normal cycle | 9.8 critical | 3.7% | 2020-02-13 |
| CVE-2021-35522 | A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP… | In your normal cycle | 9.8 critical | 3.7% | 2021-07-22 |
| CVE-2021-40408 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], base… | In your normal cycle | 9.8 critical | 3.7% | 2022-01-28 |
| CVE-2021-40409 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], base… | In your normal cycle | 9.8 critical | 3.7% | 2022-01-28 |
| CVE-2016-1245 | It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discov… | In your normal cycle | 9.8 critical | 3.7% | 2017-02-22 |
| CVE-2024-10763 | The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_aj… | In your normal cycle | 9.8 critical | 3.7% | 2025-02-13 |
| CVE-2023-49371 | RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit. | In your normal cycle | 9.8 critical | 3.7% | 2023-12-01 |
| CVE-2025-0674 | Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functiona… | In your normal cycle | 9.8 critical | 3.7% | 2025-02-07 |
| CVE-2017-7476 | Gnulib before 2017-04-26 has a heap-based buffer overflow with the TZ environment variable. The error is in the save_abbr function in time_rz.c. | In your normal cycle | 9.8 critical | 3.7% | 2017-05-02 |
| CVE-2018-18240 | Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's… | In your normal cycle | 9.8 critical | 3.7% | 2018-10-11 |
| CVE-2016-4999 | SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuild… | In your normal cycle | 9.8 critical | 3.7% | 2016-08-05 |
| CVE-2016-5008 | libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers… | In your normal cycle | 9.8 critical | 3.7% | 2016-07-13 |
| CVE-2019-20467 | An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. The device by default has a TELNET interface available (w… | In your normal cycle | 9.8 critical | 3.7% | 2021-07-22 |
| CVE-2016-10759 | The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileManager/Classes/ExtendedFileMana… | In your normal cycle | 9.8 critical | 3.7% | 2019-05-24 |
| CVE-2016-6559 | Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c of the BSD libc library may allow an attacker to read or write… | In your normal cycle | 9.8 critical | 3.7% | 2018-07-13 |
| CVE-2026-85103 | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Q… | In your normal cycle | 9.8 critical | 3.7% | 2026-09-09 |
| CVE-2026-73296 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and… | In your normal cycle | 9.4 critical | 3.7% | 2026-08-12 |
| CVE-2018-15441 | A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote attacker to execute arbitrary SQ… | In your normal cycle | 9.4 critical | 3.7% | 2018-11-28 |
| CVE-2014-9186 | A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2… | In your normal cycle | 9.8 critical | 3.7% | 2019-04-08 |
| CVE-2016-3086 | The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeMa… | In your normal cycle | 9.8 critical | 3.7% | 2017-09-05 |
| CVE-2011-1935 | pcap-linux.c in libpcap 1.1.1 before commit ea9432fabdf4b33cbc76d9437200e028f1c47c93 when snaplen is set may truncate packets, which might allow remot… | In your normal cycle | 9.8 critical | 3.6% | 2017-10-20 |
| CVE-2013-4409 | An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests. | In your normal cycle | 9.8 critical | 3.6% | 2019-11-04 |
| CVE-2014-1860 | Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities | In your normal cycle | 9.8 critical | 3.6% | 2020-01-08 |
| CVE-2014-8650 | python-requests-Kerberos through 0.5 does not handle mutual authentication | In your normal cycle | 9.8 critical | 3.6% | 2019-12-15 |
| CVE-2016-9400 | The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical mem… | In your normal cycle | 9.8 critical | 3.6% | 2017-02-22 |
| CVE-2016-6143 | SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806. | In your normal cycle | 9.8 critical | 3.6% | 2017-04-13 |
| CVE-2016-10141 | An integer overflow vulnerability was observed in the regemit function in regexp.c in Artifex Software, Inc. MuJS before fa3d30fd18c348bb4b1f3858fb860… | In your normal cycle | 9.8 critical | 3.6% | 2017-01-13 |
| CVE-2019-16733 | processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system… | In your normal cycle | 9.8 critical | 3.6% | 2019-12-13 |
| CVE-2019-16737 | The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arb… | In your normal cycle | 9.8 critical | 3.6% | 2019-12-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt