CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,891 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,991 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-1586 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file.… | In your normal cycle | 9.1 critical | 3.4% | 2022-05-16 |
| CVE-2022-34045 | Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/w… | In your normal cycle | 9.8 critical | 3.4% | 2022-07-20 |
| CVE-2018-17573 | The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of FCKeditor under fcke… | In your normal cycle | 9.8 critical | 3.4% | 2018-09-28 |
| CVE-2020-13092 | scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if… | In your normal cycle | 9.8 critical | 3.4% | 2020-05-15 |
| CVE-2016-8859 | Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, w… | In your normal cycle | 9.8 critical | 3.4% | 2017-02-13 |
| CVE-2017-6886 | An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory. | In your normal cycle | 9.8 critical | 3.4% | 2017-05-16 |
| CVE-2017-7191 | The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code vi… | In your normal cycle | 9.8 critical | 3.4% | 2017-03-27 |
| CVE-2018-6213 | In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.… | In your normal cycle | 9.8 critical | 3.4% | 2018-06-20 |
| CVE-2021-27200 | In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily pre… | In your normal cycle | 9.8 critical | 3.4% | 2021-06-11 |
| CVE-2020-28283 | Prototype pollution vulnerability in 'libnested' versions 0.0.0 through 1.5.0 allows an attacker to cause a denial of service and may lead to remote c… | In your normal cycle | 9.8 critical | 3.4% | 2020-12-29 |
| CVE-2025-49833 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in the w… | In your normal cycle | 9.8 critical | 3.4% | 2025-07-15 |
| CVE-2019-8236 | Creative Cloud Desktop Application version 4.6.1 and earlier versions have Security Bypass vulnerability. Successful exploitation could lead to Privil… | In your normal cycle | 9.8 critical | 3.4% | 2019-10-23 |
| CVE-2017-13771 | Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows rem… | In your normal cycle | 9.8 critical | 3.4% | 2017-09-07 |
| CVE-2018-12377 | A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted whil… | In your normal cycle | 9.8 critical | 3.4% | 2018-10-18 |
| CVE-2018-12378 | A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to… | In your normal cycle | 9.8 critical | 3.4% | 2018-10-18 |
| CVE-2021-0474 | In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with… | In your normal cycle | 9.8 critical | 3.4% | 2021-06-11 |
| CVE-2019-12103 | The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by a pre-authentication command injection vulner… | In your normal cycle | 9.8 critical | 3.4% | 2019-08-14 |
| CVE-2016-2071 | Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e be… | In your normal cycle | 9.8 critical | 3.4% | 2016-02-17 |
| CVE-2016-2336 | Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than this… | In your normal cycle | 9.8 critical | 3.4% | 2017-01-06 |
| CVE-2016-7923 | The ARP parser in tcpdump before 4.9.0 has a buffer overflow in print-arp.c:arp_print(). | In your normal cycle | 9.8 critical | 3.4% | 2017-01-28 |
| CVE-2017-12986 | The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13008 | The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2017-13009 | The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_print(). | In your normal cycle | 9.8 critical | 3.4% | 2017-09-14 |
| CVE-2020-24379 | WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection. | In your normal cycle | 9.8 critical | 3.4% | 2020-09-09 |
| CVE-2019-11325 | An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially… | In your normal cycle | 9.8 critical | 3.4% | 2019-11-21 |
| CVE-2019-15822 | The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal. | In your normal cycle | 9.8 critical | 3.4% | 2019-08-30 |
| CVE-2019-7160 | idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arb… | In your normal cycle | 9.8 critical | 3.4% | 2019-01-29 |
| CVE-2026-46339 | 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, al… | In your normal cycle | 10.0 critical | 3.4% | 2026-07-15 |
| CVE-2018-1287 | In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an att… | In your normal cycle | 9.8 critical | 3.4% | 2018-02-14 |
| CVE-2016-4614 | libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchO… | In your normal cycle | 9.8 critical | 3.4% | 2016-07-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt