CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,734 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,963 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-33150 | An OS command injection vulnerability exists in the js_package install functionality of Robustel R1510 3.1.16. A specially-crafted network request can… | In your normal cycle | 9.8 critical | 3.6% | 2022-10-25 |
| CVE-2019-9195 | util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive. | In your normal cycle | 9.8 critical | 3.6% | 2019-02-26 |
| CVE-2020-7623 | jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument. | In your normal cycle | 9.8 critical | 3.6% | 2020-04-02 |
| CVE-2017-13028 | The BOOTP parser in tcpdump before 4.9.2 has a buffer over-read in print-bootp.c:bootp_print(). | In your normal cycle | 9.8 critical | 3.6% | 2017-09-14 |
| CVE-2016-9180 | perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities… | In your normal cycle | 9.1 critical | 3.6% | 2016-12-22 |
| CVE-2021-46560 | The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage. | In your normal cycle | 9.8 critical | 3.6% | 2022-01-26 |
| CVE-2021-27983 | Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page. | In your normal cycle | 9.8 critical | 3.6% | 2021-12-10 |
| CVE-2012-10019 | The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versi… | In your normal cycle | 9.8 critical | 3.6% | 2025-07-19 |
| CVE-2018-0683 | Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attac… | In your normal cycle | 9.8 critical | 3.6% | 2018-11-15 |
| CVE-2018-0684 | Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R3.0 and earlier, Denbun IMAP version V3.3I R3.0 and earlier) allows remote attac… | In your normal cycle | 9.8 critical | 3.6% | 2018-11-15 |
| CVE-2017-5400 | JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks.… | In your normal cycle | 9.8 critical | 3.6% | 2018-06-11 |
| CVE-2018-16657 | In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. Th… | In your normal cycle | 9.8 critical | 3.6% | 2018-09-07 |
| CVE-2021-28119 | Twinkle Tray (aka twinkle-tray) through 1.13.3 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulner… | In your normal cycle | 9.8 critical | 3.6% | 2021-03-09 |
| CVE-2019-1971 | A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a… | In your normal cycle | 9.8 critical | 3.6% | 2019-08-08 |
| CVE-2019-13131 | Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE. | In your normal cycle | 9.8 critical | 3.6% | 2019-07-01 |
| CVE-2019-13560 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to force a blank password via the apply_sec.cgi setup_wizard parameter. | In your normal cycle | 9.8 critical | 3.6% | 2019-07-11 |
| CVE-2018-14802 | Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. The program does… | In your normal cycle | 9.8 critical | 3.6% | 2018-10-01 |
| CVE-2018-14811 | Fuji Electric V-Server 4.0.3.0 and prior, Multiple untrusted pointer dereference vulnerabilities have been identified, which may allow remote code exe… | In your normal cycle | 9.8 critical | 3.6% | 2018-09-26 |
| CVE-2018-14815 | Fuji Electric V-Server 4.0.3.0 and prior, Several out-of-bounds write vulnerabilities have been identified, which may allow remote code execution. | In your normal cycle | 9.8 critical | 3.6% | 2018-09-26 |
| CVE-2018-14817 | Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote code execution. | In your normal cycle | 9.8 critical | 3.6% | 2018-09-26 |
| CVE-2018-14819 | Fuji Electric V-Server 4.0.3.0 and prior, An out-of-bounds read vulnerability has been identified, which may allow remote code execution. | In your normal cycle | 9.8 critical | 3.6% | 2018-09-26 |
| CVE-2017-5433 | A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation contr… | In your normal cycle | 9.8 critical | 3.6% | 2018-06-11 |
| CVE-2017-5434 | A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Thu… | In your normal cycle | 9.8 critical | 3.6% | 2018-06-11 |
| CVE-2017-5438 | A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a poten… | In your normal cycle | 9.8 critical | 3.6% | 2018-06-11 |
| CVE-2017-5439 | A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. Th… | In your normal cycle | 9.8 critical | 3.6% | 2018-06-11 |
| CVE-2018-20353 | An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c in Cesanta… | In your normal cycle | 9.8 critical | 3.6% | 2019-06-10 |
| CVE-2018-20354 | An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mon… | In your normal cycle | 9.8 critical | 3.6% | 2019-06-10 |
| CVE-2018-20355 | An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose E… | In your normal cycle | 9.8 critical | 3.6% | 2019-06-10 |
| CVE-2018-20356 | An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Em… | In your normal cycle | 9.8 critical | 3.6% | 2019-06-10 |
| CVE-2018-6298 | Remote code execution in Hanwha Techwin Smartcams | In your normal cycle | 9.8 critical | 3.6% | 2018-03-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt