CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,887 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,991 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-27000 | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_ba… | In your normal cycle | 9.8 critical | 3.4% | 2022-03-15 |
| CVE-2022-27001 | Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability… | In your normal cycle | 9.8 critical | 3.4% | 2022-03-15 |
| CVE-2019-5067 | An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF… | In your normal cycle | 9.8 critical | 3.4% | 2019-09-18 |
| CVE-2026-46442 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lac… | In your normal cycle | 9.9 critical | 3.4% | 2026-06-08 |
| CVE-2020-28907 | Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors rela… | In your normal cycle | 9.8 critical | 3.4% | 2021-05-24 |
| CVE-2021-36624 | Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass… | In your normal cycle | 9.8 critical | 3.4% | 2021-07-30 |
| CVE-2018-0425 | A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, a… | In your normal cycle | 9.8 critical | 3.4% | 2018-10-05 |
| CVE-2020-28271 | Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code e… | In your normal cycle | 9.8 critical | 3.4% | 2020-11-12 |
| CVE-2022-20829 | A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security… | In your normal cycle | 9.1 critical | 3.4% | 2022-06-24 |
| CVE-2017-10804 | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain c… | In your normal cycle | 9.8 critical | 3.4% | 2017-07-04 |
| CVE-2016-6655 | An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31. A command… | In your normal cycle | 9.8 critical | 3.4% | 2017-06-13 |
| CVE-2020-8234 | A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, en… | In your normal cycle | 9.8 critical | 3.4% | 2020-08-21 |
| CVE-2021-44159 | 4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files wi… | In your normal cycle | 9.8 critical | 3.4% | 2021-12-20 |
| CVE-2020-3227 | A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthentic… | In your normal cycle | 9.8 critical | 3.4% | 2020-06-03 |
| CVE-2017-5429 | Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory cor… | In your normal cycle | 9.8 critical | 3.4% | 2018-06-11 |
| CVE-2020-22001 | HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the loc… | In your normal cycle | 9.8 critical | 3.4% | 2021-04-27 |
| CVE-2017-14648 | A global buffer overflow was discovered in the iteration_loop function in loop.c in BladeEnc version 0.94.2. The vulnerability causes an out-of-bounds… | In your normal cycle | 9.8 critical | 3.4% | 2017-09-21 |
| CVE-2022-48253 | nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server. The vul… | In your normal cycle | 9.8 critical | 3.4% | 2023-01-11 |
| CVE-2019-12165 | MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8),… | In your normal cycle | 9.8 critical | 3.4% | 2019-05-29 |
| CVE-2022-22823 | build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | In your normal cycle | 9.8 critical | 3.4% | 2022-01-10 |
| CVE-2022-22824 | defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | In your normal cycle | 9.8 critical | 3.4% | 2022-01-10 |
| CVE-2016-4606 | Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive informa… | In your normal cycle | 9.8 critical | 3.4% | 2020-02-21 |
| CVE-2018-7186 | Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a… | In your normal cycle | 9.8 critical | 3.4% | 2018-02-16 |
| CVE-2020-35858 | An issue was discovered in the prost crate before 0.6.1 for Rust. There is stack consumption via a crafted message, causing a denial of service (e.g.,… | In your normal cycle | 9.8 critical | 3.4% | 2020-12-31 |
| CVE-2020-14072 | An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin scripts. | In your normal cycle | 9.8 critical | 3.4% | 2020-06-29 |
| CVE-2019-16676 | Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked a… | In your normal cycle | 9.8 critical | 3.4% | 2019-09-30 |
| CVE-2019-5413 | An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1. | In your normal cycle | 9.8 critical | 3.4% | 2019-03-21 |
| CVE-2018-3608 | A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacke… | In your normal cycle | 9.8 critical | 3.4% | 2018-07-06 |
| CVE-2021-41280 | Sharetribe Go is a source available marketplace software. In affected versions operating system command injection is possible on installations of Shar… | In your normal cycle | 9.8 critical | 3.4% | 2021-11-19 |
| CVE-2024-24402 | An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component. | In your normal cycle | 9.8 critical | 3.4% | 2024-02-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt