CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,729 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,962 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-7857 | FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxv… | In your normal cycle | 9.8 critical | 3.6% | 2017-04-14 |
| CVE-2013-1591 | Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent a… | In your normal cycle | 9.8 critical | 3.6% | 2013-01-31 |
| CVE-2014-9187 | Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and al… | In your normal cycle | 9.8 critical | 3.6% | 2019-03-25 |
| CVE-2018-16550 | TeamViewer 10.x through 13.x allows remote attackers to bypass the brute-force authentication protection mechanism by skipping the "Cancel" step, whic… | In your normal cycle | 9.8 critical | 3.6% | 2018-09-05 |
| CVE-2019-17556 | Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being d… | In your normal cycle | 9.8 critical | 3.6% | 2019-12-04 |
| CVE-2017-16616 | An exploitable vulnerability exists in the YAML parsing functionality in the YAMLParser method in Interfaces.py in PyAnyAPI before 0.6.1. A YAML parse… | In your normal cycle | 9.8 critical | 3.6% | 2017-11-08 |
| CVE-2022-23088 | The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a Fre… | In your normal cycle | 9.8 critical | 3.6% | 2024-02-15 |
| CVE-2019-6334 | HP LaserJet, PageWide, OfficeJet Enterprise, and LaserJet Managed Printers have a solution to check application signature that may allow potential exe… | In your normal cycle | 9.8 critical | 3.6% | 2019-10-16 |
| CVE-2026-18601 | A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the compone… | In your normal cycle | 9.8 critical | 3.6% | 2026-08-03 |
| CVE-2026-18602 | A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of… | In your normal cycle | 9.8 critical | 3.6% | 2026-08-03 |
| CVE-2026-18614 | A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component… | In your normal cycle | 9.8 critical | 3.6% | 2026-08-03 |
| CVE-2026-18615 | A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bi… | In your normal cycle | 9.8 critical | 3.6% | 2026-08-03 |
| CVE-2026-18616 | A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the… | In your normal cycle | 9.8 critical | 3.6% | 2026-08-03 |
| CVE-2026-18684 | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the compon… | In your normal cycle | 9.8 critical | 3.6% | 2026-08-03 |
| CVE-2026-18685 | A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the comp… | In your normal cycle | 9.8 critical | 3.6% | 2026-08-04 |
| CVE-2022-32765 | An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted… | In your normal cycle | 9.8 critical | 3.6% | 2022-10-25 |
| CVE-2021-42377 | An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell co… | In your normal cycle | 9.8 critical | 3.6% | 2021-11-15 |
| CVE-2019-9927 | Caret before 2019-02-22 allows Remote Code Execution. | In your normal cycle | 9.8 critical | 3.6% | 2019-03-22 |
| CVE-2017-8287 | FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psa… | In your normal cycle | 9.8 critical | 3.6% | 2017-04-27 |
| CVE-2018-9148 | Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass… | In your normal cycle | 9.8 critical | 3.6% | 2018-03-30 |
| CVE-2018-6639 | An out-of-bounds write (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. A size used by memmove is read from the input fil… | In your normal cycle | 9.8 critical | 3.6% | 2018-02-28 |
| CVE-2019-1010245 | The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can exe… | In your normal cycle | 9.8 critical | 3.6% | 2019-07-19 |
| CVE-2017-12757 | Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8… | In your normal cycle | 9.8 critical | 3.6% | 2019-05-09 |
| CVE-2017-12759 | Ynet Interactive - http://demo.ynetinteractive.com/soa/ SOA School Management 3.0 is affected by: SQL Injection. The impact is: Code execution (remote… | In your normal cycle | 9.8 critical | 3.6% | 2019-05-09 |
| CVE-2019-3951 | Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service (memory corruption) du… | In your normal cycle | 9.8 critical | 3.6% | 2019-12-12 |
| CVE-2018-0222 | A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by… | In your normal cycle | 10.0 critical | 3.6% | 2018-05-17 |
| CVE-2020-12125 | A remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execut… | In your normal cycle | 9.8 critical | 3.6% | 2020-10-02 |
| CVE-2020-28904 | Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious com… | In your normal cycle | 9.8 critical | 3.6% | 2021-05-24 |
| CVE-2017-7239 | Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of serv… | In your normal cycle | 9.8 critical | 3.6% | 2017-04-10 |
| CVE-2017-2768 | EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC N… | In your normal cycle | 9.8 critical | 3.6% | 2017-02-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt