CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,891 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,991 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-16028 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to by… | In your normal cycle | 9.8 critical | 3.4% | 2020-09-23 |
| CVE-2018-5091 | A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable cr… | In your normal cycle | 9.8 critical | 3.4% | 2018-06-11 |
| CVE-2014-8362 | Vivint Sky Control Panel 1.1.1.9926 allows remote attackers to enable and disable the alarm system and modify other security settings via the Web-enab… | In your normal cycle | 9.8 critical | 3.3% | 2017-01-23 |
| CVE-2023-37999 | Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0. | In your normal cycle | 9.8 critical | 3.3% | 2024-05-17 |
| CVE-2018-17160 | In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a gu… | In your normal cycle | 10.0 critical | 3.3% | 2018-12-04 |
| CVE-2024-24112 | xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter. | In your normal cycle | 9.8 critical | 3.3% | 2024-02-06 |
| CVE-2013-7465 | Ice Cold Apps Servers Ultimate 6.0.2(12) does not require authentication for TELNET, SSH, or FTP, which allows remote attackers to execute arbitrary c… | In your normal cycle | 9.8 critical | 3.3% | 2018-10-05 |
| CVE-2019-19033 | Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by usin… | In your normal cycle | 9.8 critical | 3.3% | 2019-11-21 |
| CVE-2017-12187 | xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly exe… | In your normal cycle | 9.8 critical | 3.3% | 2018-01-24 |
| CVE-2017-18025 | cgi-bin/drknow.cgi in Innotube ITGuard-Manager 0.0.0.1 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the userna… | In your normal cycle | 9.8 critical | 3.3% | 2018-01-09 |
| CVE-2022-33198 | Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress. | In your normal cycle | 9.8 critical | 3.3% | 2022-07-21 |
| CVE-2022-34487 | Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress. | In your normal cycle | 9.8 critical | 3.3% | 2022-07-21 |
| CVE-2025-1562 | The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unautho… | In your normal cycle | 9.8 critical | 3.3% | 2025-06-18 |
| CVE-2024-4620 | The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way th… | In your normal cycle | 9.8 critical | 3.3% | 2024-06-07 |
| CVE-2022-24693 | Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by… | In your normal cycle | 9.8 critical | 3.3% | 2022-03-30 |
| CVE-2018-12670 | SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow OS Command Injection. | In your normal cycle | 9.8 critical | 3.3% | 2018-10-19 |
| CVE-2018-15616 | A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization… | In your normal cycle | 9.0 critical | 3.3% | 2018-10-17 |
| CVE-2021-41511 | The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass auth… | In your normal cycle | 9.8 critical | 3.3% | 2021-10-04 |
| CVE-2016-7435 | The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.4… | In your normal cycle | 9.1 critical | 3.3% | 2016-10-05 |
| CVE-2016-0693 | Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows remote attackers to affect confidentiality, integrity, and availability via vectors… | In your normal cycle | 9.8 critical | 3.3% | 2016-04-21 |
| CVE-2016-3953 | The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a hardcoded enc… | In your normal cycle | 9.8 critical | 3.3% | 2018-02-06 |
| CVE-2022-39073 | There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerabil… | In your normal cycle | 9.8 critical | 3.3% | 2023-01-06 |
| CVE-2017-12861 | The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-… | In your normal cycle | 9.8 critical | 3.3% | 2017-10-10 |
| CVE-2017-7876 | This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the iss… | In your normal cycle | 10.0 critical | 3.3% | 2017-06-15 |
| CVE-2021-34080 | OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metachara… | In your normal cycle | 9.8 critical | 3.3% | 2022-06-02 |
| CVE-2020-12501 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8… | In your normal cycle | 9.8 critical | 3.3% | 2020-10-15 |
| CVE-2020-21651 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method… | In your normal cycle | 9.8 critical | 3.3% | 2021-10-06 |
| CVE-2022-38649 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Airf… | In your normal cycle | 9.8 critical | 3.3% | 2022-11-22 |
| CVE-2021-25912 | Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code ex… | In your normal cycle | 9.8 critical | 3.3% | 2021-02-02 |
| CVE-2021-25927 | Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote c… | In your normal cycle | 9.8 critical | 3.3% | 2021-04-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt