CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,734 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,963 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-28895 | A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privi… | In your normal cycle | 9.8 critical | 3.5% | 2022-05-10 |
| CVE-2022-28896 | A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate priv… | In your normal cycle | 9.8 critical | 3.5% | 2022-05-10 |
| CVE-2022-28901 | A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privilege… | In your normal cycle | 9.8 critical | 3.5% | 2022-05-10 |
| CVE-2018-17161 | In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), and 12.0-RELEASE-p1, insufficient validation of network-provided data i… | In your normal cycle | 9.8 critical | 3.5% | 2019-01-03 |
| CVE-2008-3612 | The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which all… | In your normal cycle | 9.8 critical | 3.5% | 2008-09-11 |
| CVE-2019-9631 | Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. | In your normal cycle | 9.8 critical | 3.5% | 2019-03-08 |
| CVE-2018-14804 | Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution. | In your normal cycle | 9.8 critical | 3.5% | 2018-10-01 |
| CVE-2015-6473 | WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation. | In your normal cycle | 9.8 critical | 3.5% | 2017-08-22 |
| CVE-2019-11076 | Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request. | In your normal cycle | 9.8 critical | 3.5% | 2019-04-23 |
| CVE-2016-9898 | Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Fir… | In your normal cycle | 9.8 critical | 3.5% | 2018-06-11 |
| CVE-2021-23165 | A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and den… | In your normal cycle | 9.8 critical | 3.5% | 2022-03-16 |
| CVE-2019-10746 | mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or mo… | In your normal cycle | 9.8 critical | 3.5% | 2019-08-23 |
| CVE-2019-19459 | An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-1945… | In your normal cycle | 9.8 critical | 3.5% | 2019-12-03 |
| CVE-2014-2552 | Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote attackers… | In your normal cycle | 9.8 critical | 3.5% | 2018-04-27 |
| CVE-2022-32847 | This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Mo… | In your normal cycle | 9.1 critical | 3.5% | 2022-09-23 |
| CVE-2021-25915 | Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote c… | In your normal cycle | 9.8 critical | 3.5% | 2021-03-09 |
| CVE-2021-25916 | Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote… | In your normal cycle | 9.8 critical | 3.5% | 2021-03-16 |
| CVE-2020-13376 | SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply cookie. | In your normal cycle | 9.0 critical | 3.5% | 2020-08-07 |
| CVE-2016-7794 | sociomantic-tsunami git-hub before 0.10.3 allows remote attackers to execute arbitrary code via a crafted repository name. | In your normal cycle | 9.8 critical | 3.5% | 2017-01-19 |
| CVE-2026-48362 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resul… | In your normal cycle | 10.0 critical | 3.5% | 2026-08-11 |
| CVE-2026-76195 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabilit… | In your normal cycle | 10.0 critical | 3.5% | 2026-08-25 |
| CVE-2026-76197 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabilit… | In your normal cycle | 10.0 critical | 3.5% | 2026-08-25 |
| CVE-2022-24311 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by insert… | In your normal cycle | 9.8 critical | 3.5% | 2022-02-09 |
| CVE-2017-14586 | The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at… | In your normal cycle | 9.8 critical | 3.5% | 2017-11-27 |
| CVE-2022-35201 | Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability. | In your normal cycle | 9.8 critical | 3.5% | 2022-08-19 |
| CVE-2022-37601 | Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects… | In your normal cycle | 9.8 critical | 3.5% | 2022-10-12 |
| CVE-2016-6558 | A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface… | In your normal cycle | 9.8 critical | 3.5% | 2018-07-13 |
| CVE-2020-9409 | The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperR… | In your normal cycle | 9.8 critical | 3.5% | 2020-05-20 |
| CVE-2014-5014 | The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid ch… | In your normal cycle | 9.8 critical | 3.5% | 2018-04-25 |
| CVE-2020-21012 | Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrar… | In your normal cycle | 9.8 critical | 3.5% | 2021-10-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt