CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,746 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,968 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-33443 | Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrary admini… | In your normal cycle | 9.8 critical | 3.5% | 2023-06-08 |
| CVE-2022-42493 | Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reques… | In your normal cycle | 9.8 critical | 3.5% | 2023-01-26 |
| CVE-2021-45414 | A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver… | In your normal cycle | 9.8 critical | 3.5% | 2022-02-28 |
| CVE-2022-0730 | Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. | In your normal cycle | 9.8 critical | 3.5% | 2022-03-03 |
| CVE-2018-7811 | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could a… | In your normal cycle | 9.8 critical | 3.5% | 2018-11-30 |
| CVE-2020-6989 | In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, a buffer overflow in the web server allows r… | In your normal cycle | 9.8 critical | 3.5% | 2020-03-24 |
| CVE-2017-1710 | A vulnerability in the Service Assistant GUI in IBM Storwize V7000 (2076) 8.1 could allow a remote attacker to perform a privilege escalation. IBM X-F… | In your normal cycle | 9.8 critical | 3.5% | 2017-11-13 |
| CVE-2022-28397 | An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. N… | In your normal cycle | 9.8 critical | 3.5% | 2022-04-12 |
| CVE-2018-18912 | An issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs when a malicious POST request ha… | In your normal cycle | 9.8 critical | 3.5% | 2019-05-13 |
| CVE-2018-5768 | A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted password parameter for the COO… | In your normal cycle | 9.8 critical | 3.5% | 2018-03-20 |
| CVE-2018-19355 | modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute a… | In your normal cycle | 9.8 critical | 3.5% | 2018-11-19 |
| CVE-2019-12042 | Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda prod… | In your normal cycle | 9.8 critical | 3.5% | 2019-05-23 |
| CVE-2017-9772 | Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marke… | In your normal cycle | 9.8 critical | 3.5% | 2017-06-23 |
| CVE-2023-3533 | Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attack… | In your normal cycle | 9.8 critical | 3.5% | 2023-11-28 |
| CVE-2017-16088 | The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire… | In your normal cycle | 10.0 critical | 3.5% | 2018-06-07 |
| CVE-2018-14818 | WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior have a stack-based buffer overflow vulnerabi… | In your normal cycle | 9.8 critical | 3.5% | 2018-10-08 |
| CVE-2020-25066 | A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or… | In your normal cycle | 10.0 critical | 3.5% | 2020-12-22 |
| CVE-2021-27468 | The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vul… | In your normal cycle | 10.0 critical | 3.5% | 2022-03-23 |
| CVE-2016-4564 | The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in attempting to loc… | In your normal cycle | 9.8 critical | 3.5% | 2016-06-04 |
| CVE-2016-7939 | The GRE parser in tcpdump before 4.9.0 has a buffer overflow in print-gre.c, multiple functions. | In your normal cycle | 9.8 critical | 3.5% | 2017-01-28 |
| CVE-2019-5490 | Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that coul… | In your normal cycle | 9.8 critical | 3.5% | 2019-03-21 |
| CVE-2020-5599 | TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model… | In your normal cycle | 9.8 critical | 3.5% | 2020-07-07 |
| CVE-2015-5334 | Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible… | In your normal cycle | 9.8 critical | 3.5% | 2020-01-23 |
| CVE-2021-3657 | A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMA… | In your normal cycle | 9.8 critical | 3.5% | 2022-02-18 |
| CVE-2017-7856 | LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in v… | In your normal cycle | 9.8 critical | 3.5% | 2017-04-14 |
| CVE-2018-15715 | Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable… | In your normal cycle | 9.8 critical | 3.5% | 2018-11-30 |
| CVE-2018-18753 | Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. | In your normal cycle | 9.8 critical | 3.5% | 2018-10-29 |
| CVE-2021-32708 | Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under cert… | In your normal cycle | 9.8 critical | 3.5% | 2021-06-24 |
| CVE-2019-18364 | In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution. | In your normal cycle | 9.8 critical | 3.5% | 2019-10-31 |
| CVE-2017-7728 | On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incor… | In your normal cycle | 9.8 critical | 3.5% | 2017-07-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt