CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,734 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,963 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-20217 | D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi(… | In your normal cycle | 9.8 critical | 3.6% | 2020-01-29 |
| CVE-2017-9119 | The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application c… | In your normal cycle | 9.8 critical | 3.6% | 2017-05-21 |
| CVE-2018-9285 | Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.384… | In your normal cycle | 9.8 critical | 3.6% | 2018-04-04 |
| CVE-2019-17510 | D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /… | In your normal cycle | 9.8 critical | 3.6% | 2019-10-11 |
| CVE-2022-27357 | Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers… | In your normal cycle | 9.8 critical | 3.6% | 2022-04-08 |
| CVE-2020-15086 | In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification… | In your normal cycle | 9.8 critical | 3.6% | 2020-07-29 |
| CVE-2020-26154 | url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a… | In your normal cycle | 9.8 critical | 3.6% | 2020-09-30 |
| CVE-2020-9670 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to pr… | In your normal cycle | 9.8 critical | 3.6% | 2020-07-17 |
| CVE-2017-8045 | In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being co… | In your normal cycle | 9.8 critical | 3.6% | 2017-11-27 |
| CVE-2019-7271 | Nortek Linear eMerge 50P/5000P devices have Default Credentials. | In your normal cycle | 9.8 critical | 3.6% | 2019-07-01 |
| CVE-2016-9534 | tif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members. Reported a… | In your normal cycle | 9.8 critical | 3.6% | 2016-11-22 |
| CVE-2026-26831 | textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious… | In your normal cycle | 9.8 critical | 3.6% | 2026-03-25 |
| CVE-2014-4966 | Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which a… | In your normal cycle | 9.8 critical | 3.6% | 2020-02-18 |
| CVE-2014-4967 | Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansibl… | In your normal cycle | 9.8 critical | 3.6% | 2020-02-18 |
| CVE-2019-15224 | The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Vers… | In your normal cycle | 9.8 critical | 3.6% | 2019-08-19 |
| CVE-2020-1467 | An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability c… | In your normal cycle | 10.0 critical | 3.5% | 2020-08-17 |
| CVE-2025-41243 | Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable whe… | In your normal cycle | 10.0 critical | 3.5% | 2025-09-16 |
| CVE-2021-27514 | EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (su… | In your normal cycle | 9.8 critical | 3.5% | 2021-02-22 |
| CVE-2021-3375 | ActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or arbitrary code execution. | In your normal cycle | 9.8 critical | 3.5% | 2021-02-15 |
| CVE-2013-2512 | The ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument withi… | In your normal cycle | 9.8 critical | 3.5% | 2021-01-26 |
| CVE-2025-29972 | Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. | In your normal cycle | 9.9 critical | 3.5% | 2025-05-08 |
| CVE-2022-31813 | Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop me… | In your normal cycle | 9.8 critical | 3.5% | 2022-06-09 |
| CVE-2017-9385 | An issue was discovered on Vera Veralite 1.7.481 devices. The device has an additional OpenWRT interface in addition to the standard web interface whi… | In your normal cycle | 9.8 critical | 3.5% | 2019-06-17 |
| CVE-2017-3221 | Blind SQL injection in Inmarsat AmosConnect 8 login form allows remote attackers to access user credentials, including user names and passwords. | In your normal cycle | 9.8 critical | 3.5% | 2017-07-22 |
| CVE-2024-22252 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative pr… | In your normal cycle | 9.3 critical | 3.5% | 2024-03-05 |
| CVE-2012-0803 | The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as par… | In your normal cycle | 9.8 critical | 3.5% | 2017-08-08 |
| CVE-2015-2320 | The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback. | In your normal cycle | 9.8 critical | 3.5% | 2018-01-08 |
| CVE-2014-10075 | The karo gem 2.3.8 for Ruby allows Remote command injection via the host field. | In your normal cycle | 9.8 critical | 3.5% | 2018-10-05 |
| CVE-2019-0813 | An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'Windows Admin… | In your normal cycle | 9.8 critical | 3.5% | 2019-04-09 |
| CVE-2016-3028 | IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenti… | In your normal cycle | 9.1 critical | 3.5% | 2016-11-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt