CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,729 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,962 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-82688 | A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the fi… | In your normal cycle | 9.1 critical | 3.6% | 2026-08-31 |
| CVE-2026-82690 | A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/… | In your normal cycle | 9.1 critical | 3.6% | 2026-08-31 |
| CVE-2026-82691 | A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality… | In your normal cycle | 9.1 critical | 3.6% | 2026-08-31 |
| CVE-2026-85222 | A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_cente… | In your normal cycle | 9.1 critical | 3.6% | 2026-09-03 |
| CVE-2026-85224 | A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component… | In your normal cycle | 9.1 critical | 3.6% | 2026-09-03 |
| CVE-2026-90702 | A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument… | In your normal cycle | 9.1 critical | 3.6% | 2026-09-14 |
| CVE-2026-90703 | A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such ma… | In your normal cycle | 9.1 critical | 3.6% | 2026-09-14 |
| CVE-2021-39377 | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL… | In your normal cycle | 9.8 critical | 3.6% | 2021-09-01 |
| CVE-2018-1000827 | Ubilling version <= 0.9.2 contains a Other/Unknown vulnerability in user-controlled parameter that can result in Disclosure of confidential data, deni… | In your normal cycle | 9.8 critical | 3.6% | 2018-12-20 |
| CVE-2020-13091 | pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an… | In your normal cycle | 9.8 critical | 3.6% | 2020-05-15 |
| CVE-2020-7614 | npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validation… | In your normal cycle | 9.8 critical | 3.6% | 2020-04-07 |
| CVE-2021-23389 | The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. | In your normal cycle | 9.8 critical | 3.6% | 2021-07-12 |
| CVE-2016-5297 | An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affects… | In your normal cycle | 9.8 critical | 3.6% | 2018-06-11 |
| CVE-2016-9533 | tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers. Reported as MSVR 35094, aka "PixarLog horizontalDif… | In your normal cycle | 9.8 critical | 3.6% | 2016-11-22 |
| CVE-2017-5205 | The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print(). | In your normal cycle | 9.8 critical | 3.6% | 2017-01-28 |
| CVE-2017-5636 | In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection… | In your normal cycle | 9.8 critical | 3.6% | 2017-10-19 |
| CVE-2018-16974 | An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /fileman… | In your normal cycle | 9.8 critical | 3.6% | 2018-09-12 |
| CVE-2017-16226 | The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the glo… | In your normal cycle | 9.8 critical | 3.6% | 2018-06-07 |
| CVE-2023-4490 | The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injectio… | In your normal cycle | 9.8 critical | 3.6% | 2023-09-25 |
| CVE-2017-7824 | A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect val… | In your normal cycle | 9.8 critical | 3.6% | 2018-06-11 |
| CVE-2019-19628 | In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escal… | In your normal cycle | 9.8 critical | 3.6% | 2020-01-05 |
| CVE-2024-10811 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthent… | In your normal cycle | 9.8 critical | 3.6% | 2025-01-14 |
| CVE-2022-26496 | In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by… | In your normal cycle | 9.8 critical | 3.6% | 2022-03-06 |
| CVE-2024-43498 | .NET and Visual Studio Remote Code Execution Vulnerability | In your normal cycle | 9.8 critical | 3.6% | 2024-11-12 |
| CVE-2022-40664 | Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher. | In your normal cycle | 9.8 critical | 3.6% | 2022-10-12 |
| CVE-2019-19836 | AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcm… | In your normal cycle | 9.8 critical | 3.6% | 2020-01-22 |
| CVE-2016-5453 | Unspecified vulnerability in the ILOM component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect confidentiali… | In your normal cycle | 9.8 critical | 3.6% | 2016-07-21 |
| CVE-2021-23449 | This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine. | In your normal cycle | 9.8 critical | 3.6% | 2021-10-18 |
| CVE-2020-6932 | An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versio… | In your normal cycle | 10.0 critical | 3.6% | 2020-08-12 |
| CVE-2020-18717 | SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php. | In your normal cycle | 9.8 critical | 3.6% | 2021-02-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt