CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,734 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,963 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-23626 | A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerabilit… | In your normal cycle | 9.0 critical | 3.5% | 2024-01-26 |
| CVE-2024-23627 | A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulne… | In your normal cycle | 9.0 critical | 3.5% | 2024-01-26 |
| CVE-2017-6050 | A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which m… | In your normal cycle | 9.8 critical | 3.5% | 2017-06-21 |
| CVE-2021-27944 | Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthentica… | In your normal cycle | 9.8 critical | 3.5% | 2021-08-26 |
| CVE-2020-0594 | Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthentic… | In your normal cycle | 9.8 critical | 3.5% | 2020-06-15 |
| CVE-2016-7109 | Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a diff… | In your normal cycle | 9.8 critical | 3.5% | 2016-09-07 |
| CVE-2019-11005 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remot… | In your normal cycle | 9.8 critical | 3.5% | 2019-04-08 |
| CVE-2021-40719 | Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary method invocation whe… | In your normal cycle | 9.8 critical | 3.5% | 2021-10-21 |
| CVE-2019-12148 | The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerabil… | In your normal cycle | 9.8 critical | 3.5% | 2019-10-22 |
| CVE-2018-10617 | Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer where a value larger than the buff… | In your normal cycle | 9.8 critical | 3.5% | 2018-06-18 |
| CVE-2018-10621 | Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length stack buffer where a value larger than the buf… | In your normal cycle | 9.8 critical | 3.5% | 2018-06-18 |
| CVE-2018-10623 | Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operations on a memory buffer where the position can be… | In your normal cycle | 9.8 critical | 3.5% | 2018-06-18 |
| CVE-2015-7541 | The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attac… | In your normal cycle | 10.0 critical | 3.5% | 2016-01-08 |
| CVE-2018-15747 | The default configuration of glot-www through 2018-05-19 allows remote attackers to execute arbitrary code because glot-code-runner supports os.system… | In your normal cycle | 9.8 critical | 3.5% | 2019-06-21 |
| CVE-2017-16764 | An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in django_make_app 0.1.3. A YAML par… | In your normal cycle | 9.8 critical | 3.5% | 2017-11-10 |
| CVE-2020-24384 | A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could… | In your normal cycle | 9.8 critical | 3.5% | 2020-11-10 |
| CVE-2024-9290 | The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and… | In your normal cycle | 9.8 critical | 3.5% | 2024-12-13 |
| CVE-2019-7164 | SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. | In your normal cycle | 9.8 critical | 3.5% | 2019-02-20 |
| CVE-2020-11673 | An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone… | In your normal cycle | 9.8 critical | 3.5% | 2020-04-13 |
| CVE-2021-42911 | A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfun… | In your normal cycle | 9.8 critical | 3.5% | 2022-03-29 |
| CVE-2021-43484 | A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension o… | In your normal cycle | 9.8 critical | 3.5% | 2022-03-31 |
| CVE-2018-6667 | Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to exec… | In your normal cycle | 10.0 critical | 3.5% | 2018-06-26 |
| CVE-2022-46366 | Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17… | In your normal cycle | 9.8 critical | 3.5% | 2022-12-02 |
| CVE-2017-6551 | Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Con… | In your normal cycle | 9.8 critical | 3.5% | 2017-05-02 |
| CVE-2017-9634 | Mitsubishi E-Designer, Version 7.52 Build 344 contains two code sections which may be exploited to allow an attacker to overwrite arbitrary memory loc… | In your normal cycle | 9.8 critical | 3.5% | 2018-04-17 |
| CVE-2017-9636 | Mitsubishi E-Designer, Version 7.52 Build 344 contains five code sections which may be exploited to overwrite the heap. This can result in arbitrary c… | In your normal cycle | 9.8 critical | 3.5% | 2018-04-17 |
| CVE-2017-9638 | Mitsubishi E-Designer, Version 7.52 Build 344 contains six code sections which may be exploited to overwrite the stack. This can result in arbitrary c… | In your normal cycle | 9.8 critical | 3.5% | 2018-04-17 |
| CVE-2016-8348 | An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Lie… | In your normal cycle | 9.8 critical | 3.5% | 2017-02-13 |
| CVE-2026-19598 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to,… | In your normal cycle | 9.8 critical | 3.5% | 2026-08-15 |
| CVE-2022-23900 | A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized… | In your normal cycle | 9.8 critical | 3.5% | 2022-04-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt