CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,734 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,963 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-11344 | data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-ph… | In your normal cycle | 9.8 critical | 3.6% | 2019-04-19 |
| CVE-2016-6406 | Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA)… | In your normal cycle | 9.8 critical | 3.6% | 2016-09-22 |
| CVE-2025-69258 | A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key… | In your normal cycle | 9.8 critical | 3.6% | 2026-01-08 |
| CVE-2022-0547 | OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of defe… | In your normal cycle | 9.8 critical | 3.6% | 2022-03-18 |
| CVE-2021-29393 | Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated user… | In your normal cycle | 9.8 critical | 3.6% | 2022-02-04 |
| CVE-2023-23924 | Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters… | In your normal cycle | 10.0 critical | 3.6% | 2023-02-01 |
| CVE-2017-7784 | A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in… | In your normal cycle | 9.8 critical | 3.6% | 2018-06-11 |
| CVE-2018-0321 | A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invoc… | In your normal cycle | 9.8 critical | 3.6% | 2018-06-07 |
| CVE-2016-2230 | OpenELEC and RasPlex devices have a hardcoded password for the root account, which makes it easier for remote attackers to obtain access via an SSH se… | In your normal cycle | 9.8 critical | 3.6% | 2016-02-08 |
| CVE-2017-5215 | The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a rename attack that bypasses a "safe file extension" protecti… | In your normal cycle | 9.8 critical | 3.6% | 2017-05-17 |
| CVE-2016-10327 | LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF function in vc… | In your normal cycle | 9.8 critical | 3.6% | 2017-04-14 |
| CVE-2026-19348 | A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fnam… | In your normal cycle | 9.8 critical | 3.6% | 2026-08-09 |
| CVE-2026-4163 | A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the… | In your normal cycle | 9.8 critical | 3.6% | 2026-03-16 |
| CVE-2026-4164 | A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of th… | In your normal cycle | 9.8 critical | 3.6% | 2026-03-16 |
| CVE-2022-27276 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the f… | In your normal cycle | 9.8 critical | 3.6% | 2022-04-10 |
| CVE-2017-15718 | The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications… | In your normal cycle | 9.8 critical | 3.6% | 2018-01-24 |
| CVE-2020-36177 | RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest size. | In your normal cycle | 9.8 critical | 3.6% | 2021-01-06 |
| CVE-2019-11235 | FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is… | In your normal cycle | 9.8 critical | 3.6% | 2019-04-22 |
| CVE-2025-23211 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to ex… | In your normal cycle | 9.9 critical | 3.6% | 2025-01-28 |
| CVE-2004-2776 | go.cgi in GoScript 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) query string or (2) artarchive parame… | In your normal cycle | 9.8 critical | 3.6% | 2019-12-31 |
| CVE-2022-30292 | Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call. | In your normal cycle | 10.0 critical | 3.6% | 2022-05-04 |
| CVE-2015-6816 | ganglia-web before 3.7.1 allows remote attackers to bypass authentication. | In your normal cycle | 9.8 critical | 3.6% | 2017-08-09 |
| CVE-2019-5016 | An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of… | In your normal cycle | 9.1 critical | 3.6% | 2019-06-17 |
| CVE-2022-30511 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4. | In your normal cycle | 9.8 critical | 3.6% | 2022-06-02 |
| CVE-2024-22061 | A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbi… | In your normal cycle | 9.8 critical | 3.6% | 2024-04-19 |
| CVE-2017-7550 | A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attack… | In your normal cycle | 9.8 critical | 3.6% | 2017-11-21 |
| CVE-2020-11928 | In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query paramete… | In your normal cycle | 9.8 critical | 3.6% | 2020-04-20 |
| CVE-2015-8857 | The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow… | In your normal cycle | 9.8 critical | 3.6% | 2017-01-23 |
| CVE-2026-56782 | Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers… | In your normal cycle | 9.8 critical | 3.6% | 2026-06-29 |
| CVE-2019-17006 | In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the… | In your normal cycle | 9.8 critical | 3.6% | 2020-10-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt