CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,729 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,962 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-17364 | The processCommandUploadLog() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute… | In your normal cycle | 9.8 critical | 3.6% | 2019-12-13 |
| CVE-2019-19333 | In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits"… | In your normal cycle | 9.8 critical | 3.6% | 2019-12-06 |
| CVE-2022-47003 | A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request. | In your normal cycle | 9.8 critical | 3.6% | 2023-02-01 |
| CVE-2021-27573 | An issue was discovered in Emote Remote Mouse through 4.0.0.0. Remote unauthenticated users can execute arbitrary code via crafted UDP packets with no… | In your normal cycle | 9.8 critical | 3.6% | 2021-05-07 |
| CVE-2020-8570 | Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying mul… | In your normal cycle | 9.1 critical | 3.6% | 2021-01-21 |
| CVE-2020-6770 | Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on t… | In your normal cycle | 10.0 critical | 3.6% | 2020-02-07 |
| CVE-2020-13916 | A stack buffer overflow in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute code via an unauthenticated c… | In your normal cycle | 9.8 critical | 3.6% | 2020-07-28 |
| CVE-2019-10784 | phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area,… | In your normal cycle | 9.6 critical | 3.6% | 2020-02-04 |
| CVE-2023-26134 | Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails… | In your normal cycle | 9.8 critical | 3.6% | 2023-06-28 |
| CVE-2023-0947 | Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3. | In your normal cycle | 9.8 critical | 3.6% | 2023-02-22 |
| CVE-2018-20817 | SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob data into a… | In your normal cycle | 9.8 critical | 3.6% | 2019-04-19 |
| CVE-2018-19783 | Kentix MultiSensor-LAN 5.63.00 devices and previous allow Authentication Bypass via an Alternate Path or Channel. | In your normal cycle | 9.8 critical | 3.6% | 2019-03-21 |
| CVE-2021-21019 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful… | In your normal cycle | 9.1 critical | 3.6% | 2021-02-11 |
| CVE-2016-9480 | libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file… | In your normal cycle | 9.1 critical | 3.6% | 2016-11-29 |
| CVE-2020-8178 | Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks. | In your normal cycle | 9.8 critical | 3.6% | 2020-07-15 |
| CVE-2019-10950 | Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telne… | In your normal cycle | 9.8 critical | 3.6% | 2019-04-30 |
| CVE-2019-14431 | In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256… | In your normal cycle | 9.8 critical | 3.6% | 2019-07-29 |
| CVE-2023-33338 | Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter. | In your normal cycle | 9.8 critical | 3.6% | 2023-05-23 |
| CVE-2021-43272 | An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 2022.11. ODA Viewer continues to… | In your normal cycle | 9.8 critical | 3.6% | 2021-11-14 |
| CVE-2018-19725 | Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a security bypas… | In your normal cycle | 9.8 critical | 3.6% | 2019-03-05 |
| CVE-2017-2345 | On Junos OS devices with SNMP enabled, a network based attacker with unfiltered access to the RE can cause the Junos OS snmpd daemon to crash and rest… | In your normal cycle | 9.8 critical | 3.6% | 2017-07-17 |
| CVE-2016-7947 | Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted response. | In your normal cycle | 9.8 critical | 3.6% | 2016-12-13 |
| CVE-2016-7948 | X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data. | In your normal cycle | 9.8 critical | 3.6% | 2016-12-13 |
| CVE-2017-12166 | OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting i… | In your normal cycle | 9.8 critical | 3.6% | 2017-10-04 |
| CVE-2019-0261 | Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for… | In your normal cycle | 9.8 critical | 3.6% | 2019-02-15 |
| CVE-2017-1002020 | Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQ… | In your normal cycle | 9.8 critical | 3.6% | 2017-09-14 |
| CVE-2017-1002021 | Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it ins… | In your normal cycle | 9.8 critical | 3.6% | 2017-09-14 |
| CVE-2017-1002022 | Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL… | In your normal cycle | 9.8 critical | 3.6% | 2017-09-14 |
| CVE-2020-25928 | The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component i… | In your normal cycle | 9.8 critical | 3.6% | 2021-08-18 |
| CVE-2023-39001 | A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows… | In your normal cycle | 9.8 critical | 3.6% | 2023-08-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt