CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,813 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,970 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-7953 | Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string. | In your normal cycle | 9.8 critical | 3.5% | 2016-12-13 |
| CVE-2018-9207 | Arbitrary file upload in jQuery Upload File <= 4.0.2 | In your normal cycle | 9.8 critical | 3.5% | 2018-11-19 |
| CVE-2019-1804 | A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an… | In your normal cycle | 9.8 critical | 3.5% | 2019-05-03 |
| CVE-2015-8298 | Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands vi… | In your normal cycle | 9.8 critical | 3.5% | 2018-09-24 |
| CVE-2018-19646 | The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because co… | In your normal cycle | 9.8 critical | 3.5% | 2018-11-28 |
| CVE-2023-46266 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. | In your normal cycle | 9.1 critical | 3.5% | 2023-12-19 |
| CVE-2023-34754 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=ed… | In your normal cycle | 9.8 critical | 3.4% | 2023-06-14 |
| CVE-2016-0903 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote… | In your normal cycle | 9.1 critical | 3.4% | 2016-09-21 |
| CVE-2018-5155 | A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash… | In your normal cycle | 9.8 critical | 3.4% | 2018-06-11 |
| CVE-2024-23653 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containe… | In your normal cycle | 9.8 critical | 3.4% | 2024-01-31 |
| CVE-2019-16239 | process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes. | In your normal cycle | 9.8 critical | 3.4% | 2019-09-17 |
| CVE-2017-16615 | An exploitable vulnerability exists in the YAML parsing functionality in the parse_yaml_query method in parser.py in MLAlchemy before 0.2.2. When proc… | In your normal cycle | 9.8 critical | 3.4% | 2017-11-08 |
| CVE-2018-3856 | An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The… | In your normal cycle | 9.9 critical | 3.4% | 2018-08-23 |
| CVE-2020-29016 | A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to… | In your normal cycle | 9.8 critical | 3.4% | 2021-01-14 |
| CVE-2021-20232 | A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential… | In your normal cycle | 9.8 critical | 3.4% | 2021-03-12 |
| CVE-2018-16530 | A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a process cre… | In your normal cycle | 9.8 critical | 3.4% | 2019-04-09 |
| CVE-2018-16957 | The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded password. Authentication to the Oracl… | In your normal cycle | 9.8 critical | 3.4% | 2018-09-18 |
| CVE-2017-10965 | An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer. | In your normal cycle | 9.8 critical | 3.4% | 2017-07-07 |
| CVE-2019-10069 | In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly. | In your normal cycle | 9.8 critical | 3.4% | 2019-05-31 |
| CVE-2019-13658 | CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and com… | In your normal cycle | 9.8 critical | 3.4% | 2019-10-02 |
| CVE-2019-7537 | An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can execute arbitrary Python command… | In your normal cycle | 9.8 critical | 3.4% | 2019-03-21 |
| CVE-2019-0938 | An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser,… | In your normal cycle | 9.0 critical | 3.4% | 2019-05-16 |
| CVE-2020-3330 | A vulnerability in the Telnet service of Cisco Small Business RV110W Wireless-N VPN Firewall Routers could allow an unauthenticated, remote attacker t… | In your normal cycle | 9.8 critical | 3.4% | 2020-07-16 |
| CVE-2017-5946 | The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an… | In your normal cycle | 9.8 critical | 3.4% | 2017-02-27 |
| CVE-2018-15386 | A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and have d… | In your normal cycle | 9.8 critical | 3.4% | 2018-10-05 |
| CVE-2020-12763 | TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow in handling RTSP packets. This… | In your normal cycle | 9.8 critical | 3.4% | 2020-05-13 |
| CVE-2023-1424 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules… | In your normal cycle | 10.0 critical | 3.4% | 2023-05-24 |
| CVE-2021-43439 | RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely | In your normal cycle | 9.8 critical | 3.4% | 2021-12-20 |
| CVE-2022-21744 | In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Pac… | In your normal cycle | 9.8 critical | 3.4% | 2022-07-06 |
| CVE-2023-36281 | An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ o… | In your normal cycle | 9.8 critical | 3.4% | 2023-08-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt