CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,879 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,991 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-13581 | An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via… | In your normal cycle | 9.8 critical | 3.4% | 2019-11-15 |
| CVE-2019-19374 | An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS… | In your normal cycle | 9.1 critical | 3.4% | 2019-12-11 |
| CVE-2021-36022 | Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Wi… | In your normal cycle | 9.1 critical | 3.4% | 2021-09-01 |
| CVE-2020-12388 | The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fire… | In your normal cycle | 10.0 critical | 3.4% | 2020-05-26 |
| CVE-2010-2446 | Rbot Reaction plugin allows command execution | In your normal cycle | 9.8 critical | 3.4% | 2019-11-06 |
| CVE-2015-7544 | redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the Super… | In your normal cycle | 9.1 critical | 3.4% | 2017-09-25 |
| CVE-2018-21162 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.0.78, EX6200 before 1.0.3.86,… | In your normal cycle | 9.8 critical | 3.4% | 2020-04-23 |
| CVE-2020-0595 | Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated… | In your normal cycle | 9.8 critical | 3.4% | 2020-06-15 |
| CVE-2020-9669 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability. Successful exploitation could lead… | In your normal cycle | 9.8 critical | 3.4% | 2020-07-17 |
| CVE-2018-11542 | A Remote Command Execution (RCE) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the execution of arbitrary com… | In your normal cycle | 9.8 critical | 3.4% | 2018-07-09 |
| CVE-2017-1002012 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code… | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2020-26167 | In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrator… | In your normal cycle | 9.8 critical | 3.4% | 2020-11-04 |
| CVE-2020-20276 | An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to… | In your normal cycle | 9.8 critical | 3.4% | 2020-12-18 |
| CVE-2017-1000374 | A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using certai… | In your normal cycle | 9.8 critical | 3.4% | 2017-06-19 |
| CVE-2018-1822 | IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to… | In your normal cycle | 9.8 critical | 3.4% | 2018-10-18 |
| CVE-2021-37422 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. | In your normal cycle | 9.8 critical | 3.4% | 2021-09-10 |
| CVE-2021-41075 | The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API. | In your normal cycle | 9.8 critical | 3.4% | 2021-10-13 |
| CVE-2019-1003040 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scrip… | In your normal cycle | 9.8 critical | 3.4% | 2019-03-28 |
| CVE-2019-1003041 | A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scri… | In your normal cycle | 9.8 critical | 3.4% | 2019-03-28 |
| CVE-2019-18641 | Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller. | In your normal cycle | 9.8 critical | 3.4% | 2020-03-20 |
| CVE-2019-18805 | An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tc… | In your normal cycle | 9.8 critical | 3.4% | 2019-11-07 |
| CVE-2022-2825 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is no… | In your normal cycle | 9.8 critical | 3.4% | 2023-03-29 |
| CVE-2008-7315 | UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands. | In your normal cycle | 9.8 critical | 3.4% | 2017-10-10 |
| CVE-2020-15916 | goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharac… | In your normal cycle | 9.8 critical | 3.4% | 2020-07-23 |
| CVE-2019-13613 | CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180502 rel.45702 (EU) and earlier… | In your normal cycle | 9.8 critical | 3.4% | 2019-07-17 |
| CVE-2019-13614 | CMD_SET_CONFIG_COUNTRY in the TP-Link Device Debug protocol in TP-Link Archer C1200 1.0.0 Build 20180502 rel.45702 and earlier is prone to a stack-bas… | In your normal cycle | 9.8 critical | 3.4% | 2019-07-17 |
| CVE-2018-1000537 | Marlin Firmware Marlin version 1.1.x and earlier contains a Buffer Overflow vulnerability in cardreader.cpp (Depending on branch/version) that can res… | In your normal cycle | 9.8 critical | 3.4% | 2018-06-26 |
| CVE-2017-13021 | The ICMPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp6.c:icmp6_print(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13022 | The IP parser in tcpdump before 4.9.2 has a buffer over-read in print-ip.c:ip_printroute(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13023 | The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt