CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,879 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,991 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-13025 | The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13029 | The PPP parser in tcpdump before 4.9.2 has a buffer over-read in print-ppp.c:print_ccp_config_options(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13030 | The PIM parser in tcpdump before 4.9.2 has a buffer over-read in print-pim.c, several functions. | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13035 | The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print_id(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13036 | The OSPFv3 parser in tcpdump before 4.9.2 has a buffer over-read in print-ospf6.c:ospf6_decode_v3(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13037 | The IP parser in tcpdump before 4.9.2 has a buffer over-read in print-ip.c:ip_printts(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13039 | The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c, several functions. | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13044 | The HNCP parser in tcpdump before 4.9.2 has a buffer over-read in print-hncp.c:dhcpv4_print(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13045 | The VQP parser in tcpdump before 4.9.2 has a buffer over-read in print-vqp.c:vqp_print(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13049 | The Rx protocol parser in tcpdump before 4.9.2 has a buffer over-read in print-rx.c:ubik_print(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13052 | The CFM parser in tcpdump before 4.9.2 has a buffer over-read in print-cfm.c:cfm_print(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13690 | The IKEv2 parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c, several functions. | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2016-9483 | The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthen… | In your normal cycle | 9.8 critical | 3.4% | 2018-07-13 |
| CVE-2018-20752 | An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV injection. More specifically, whe… | In your normal cycle | 9.8 critical | 3.4% | 2019-02-04 |
| CVE-2021-44525 | Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentic… | In your normal cycle | 9.8 critical | 3.4% | 2021-12-20 |
| CVE-2018-5225 | In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (th… | In your normal cycle | 9.9 critical | 3.4% | 2018-03-22 |
| CVE-2017-7858 | FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in… | In your normal cycle | 9.8 critical | 3.4% | 2017-04-14 |
| CVE-2018-12392 | When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due t… | In your normal cycle | 9.8 critical | 3.4% | 2019-02-28 |
| CVE-2019-1010101 | Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The… | In your normal cycle | 9.8 critical | 3.4% | 2019-07-19 |
| CVE-2015-5952 | Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter. | In your normal cycle | 9.8 critical | 3.4% | 2020-01-15 |
| CVE-2022-26188 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost. | In your normal cycle | 9.8 critical | 3.4% | 2022-03-22 |
| CVE-2022-26189 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface. | In your normal cycle | 9.8 critical | 3.4% | 2022-03-22 |
| CVE-2024-5827 | Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data… | In your normal cycle | 9.8 critical | 3.4% | 2024-06-28 |
| CVE-2018-14671 | In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerabilit… | In your normal cycle | 9.8 critical | 3.4% | 2019-08-15 |
| CVE-2020-28446 | The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js. | In your normal cycle | 9.8 critical | 3.4% | 2022-07-25 |
| CVE-2026-2701 | Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. | In your normal cycle | 9.1 critical | 3.4% | 2026-04-02 |
| CVE-2021-43035 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowin… | In your normal cycle | 9.8 critical | 3.4% | 2021-12-06 |
| CVE-2022-26997 | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability a… | In your normal cycle | 9.8 critical | 3.4% | 2022-03-15 |
| CVE-2022-26998 | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This v… | In your normal cycle | 9.8 critical | 3.4% | 2022-03-15 |
| CVE-2022-26999 | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat… | In your normal cycle | 9.8 critical | 3.4% | 2022-03-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt