CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,887 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,991 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-28272 | Prototype pollution vulnerability in 'keyget' versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service and may lead to remote code ex… | In your normal cycle | 9.8 critical | 3.4% | 2020-12-02 |
| CVE-2018-16840 | A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and clean… | In your normal cycle | 9.8 critical | 3.4% | 2018-10-31 |
| CVE-2025-59434 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated v… | In your normal cycle | 9.6 critical | 3.4% | 2025-09-22 |
| CVE-2015-7926 | eWON devices with firmware before 10.1s0 omit RBAC for I/O server information and status requests, which allows remote attackers to obtain sensitive i… | In your normal cycle | 9.9 critical | 3.4% | 2015-12-23 |
| CVE-2020-23691 | YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php. | In your normal cycle | 9.8 critical | 3.4% | 2021-05-14 |
| CVE-2023-53963 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary sh… | In your normal cycle | 9.8 critical | 3.4% | 2025-12-22 |
| CVE-2021-44079 | In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting… | In your normal cycle | 9.8 critical | 3.4% | 2021-11-22 |
| CVE-2021-37164 | A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus… | In your normal cycle | 9.8 critical | 3.4% | 2021-08-02 |
| CVE-2022-33192 | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z… | In your normal cycle | 10.0 critical | 3.4% | 2022-10-25 |
| CVE-2022-33195 | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z… | In your normal cycle | 10.0 critical | 3.4% | 2022-10-25 |
| CVE-2022-32773 | An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A sp… | In your normal cycle | 9.8 critical | 3.4% | 2022-10-25 |
| CVE-2016-7944 | Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, wh… | In your normal cycle | 9.8 critical | 3.4% | 2016-12-13 |
| CVE-2020-37123 | Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the ping and socket parameters. Attac… | In your normal cycle | 9.8 critical | 3.4% | 2026-02-05 |
| CVE-2020-10071 | The Zephyr MQTT parsing code performs insufficient checking of the length field on publish messages, allowing a buffer overflow and potentially remote… | In your normal cycle | 9.0 critical | 3.4% | 2020-06-05 |
| CVE-2019-16735 | A stack-based buffer overflow in processCommandUploadLog in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote att… | In your normal cycle | 9.8 critical | 3.4% | 2019-12-13 |
| CVE-2019-16736 | A stack-based buffer overflow in processCommandUploadSnapshot in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remot… | In your normal cycle | 9.8 critical | 3.4% | 2019-12-13 |
| CVE-2019-10074 | An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This w… | In your normal cycle | 9.8 critical | 3.4% | 2019-09-11 |
| CVE-2025-49835 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui… | In your normal cycle | 9.8 critical | 3.4% | 2025-07-15 |
| CVE-2016-2908 | IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when process… | In your normal cycle | 9.1 critical | 3.4% | 2017-02-01 |
| CVE-2021-25928 | Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote co… | In your normal cycle | 9.8 critical | 3.4% | 2021-04-26 |
| CVE-2019-9891 | The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands w… | In your normal cycle | 9.8 critical | 3.4% | 2019-05-31 |
| CVE-2022-31692 | Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatch… | In your normal cycle | 9.8 critical | 3.4% | 2022-10-31 |
| CVE-2026-90847 | A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System… | In your normal cycle | 9.1 critical | 3.4% | 2026-09-15 |
| CVE-2023-38692 | CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the… | In your normal cycle | 9.8 critical | 3.4% | 2023-08-04 |
| CVE-2020-12606 | An issue was discovered in DB Soft SGLAC before 20.05.001. The ProcedimientoGenerico method in the SVCManejador.svc webservice of the SGLAC web fronte… | In your normal cycle | 9.8 critical | 3.4% | 2020-08-17 |
| CVE-2017-4053 | Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users /… | In your normal cycle | 9.8 critical | 3.4% | 2017-07-12 |
| CVE-2016-6958 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 3.4% | 2016-10-13 |
| CVE-2017-12708 | An Improper Restriction Of Operations Within The Bounds Of A Memory Buffer issue was discovered in Advantech WebAccess versions prior to V8.2_20170817… | In your normal cycle | 9.8 critical | 3.4% | 2017-08-30 |
| CVE-2019-19905 | NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems tha… | In your normal cycle | 9.8 critical | 3.4% | 2019-12-19 |
| CVE-2016-7928 | The IPComp parser in tcpdump before 4.9.0 has a buffer overflow in print-ipcomp.c:ipcomp_print(). | In your normal cycle | 9.8 critical | 3.4% | 2017-01-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt