CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,905 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,991 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-25941 | Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remo… | In your normal cycle | 9.8 critical | 3.3% | 2021-05-14 |
| CVE-2021-25952 | Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remo… | In your normal cycle | 9.8 critical | 3.3% | 2021-07-07 |
| CVE-2021-20618 | Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remote attackers to bypass authenti… | In your normal cycle | 9.8 critical | 3.3% | 2021-01-14 |
| CVE-2017-18174 | In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a doub… | In your normal cycle | 9.8 critical | 3.3% | 2018-02-11 |
| CVE-2018-20750 | LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. | In your normal cycle | 9.8 critical | 3.3% | 2019-01-30 |
| CVE-2019-12468 | An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow… | In your normal cycle | 9.8 critical | 3.3% | 2019-07-10 |
| CVE-2022-22817 | PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expressio… | In your normal cycle | 9.8 critical | 3.3% | 2022-01-10 |
| CVE-2018-15474 | CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote… | In your normal cycle | 9.6 critical | 3.3% | 2018-09-07 |
| CVE-2019-3935 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST reque… | In your normal cycle | 9.1 critical | 3.3% | 2019-04-30 |
| CVE-2018-3197 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). The supported version that is a… | In your normal cycle | 9.8 critical | 3.3% | 2018-10-17 |
| CVE-2018-3201 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). The supported version that is a… | In your normal cycle | 9.8 critical | 3.3% | 2018-10-17 |
| CVE-2018-3259 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easil… | In your normal cycle | 9.8 critical | 3.3% | 2018-10-17 |
| CVE-2018-9091 | A critical vulnerability in the KEMP LoadMaster Operating System (LMOS) 6.0.44 through 7.2.41.2 and Long Term Support (LTS) LMOS before 7.1.35.5 relat… | In your normal cycle | 9.8 critical | 3.3% | 2018-05-25 |
| CVE-2016-9539 | tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer(). Reported as MSVR 35092. | In your normal cycle | 9.8 critical | 3.3% | 2016-11-22 |
| CVE-2021-32588 | A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and… | In your normal cycle | 9.8 critical | 3.3% | 2021-08-18 |
| CVE-2016-9492 | The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated… | In your normal cycle | 9.8 critical | 3.3% | 2018-07-13 |
| CVE-2017-16840 | The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrec… | In your normal cycle | 9.8 critical | 3.3% | 2017-11-21 |
| CVE-2019-16246 | Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code executio… | In your normal cycle | 9.8 critical | 3.3% | 2019-12-12 |
| CVE-2018-4834 | A vulnerability has been identified in Desigo PXC00-E.D V4.10 (All versions < V4.10.111), Desigo PXC00-E.D V5.00 (All versions < V5.0.171), Desigo PXC… | In your normal cycle | 9.8 critical | 3.3% | 2018-01-24 |
| CVE-2019-13354 | The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current vers… | In your normal cycle | 9.8 critical | 3.3% | 2019-07-08 |
| CVE-2020-0452 | In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution… | In your normal cycle | 9.8 critical | 3.3% | 2020-11-10 |
| CVE-2020-12830 | Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privileges through unauthorized remot… | In your normal cycle | 9.8 critical | 3.3% | 2020-10-27 |
| CVE-2022-32269 | In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Explorer core).… | In your normal cycle | 9.8 critical | 3.3% | 2022-06-03 |
| CVE-2022-20841 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to exec… | In your normal cycle | 9.0 critical | 3.3% | 2022-08-10 |
| CVE-2018-18068 | The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any EL3 (the… | In your normal cycle | 9.8 critical | 3.3% | 2019-04-04 |
| CVE-2020-3850 | A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able t… | In your normal cycle | 9.8 critical | 3.3% | 2020-04-01 |
| CVE-2016-7663 | An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. Th… | In your normal cycle | 9.8 critical | 3.3% | 2017-02-20 |
| CVE-2022-30541 | An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A sp… | In your normal cycle | 9.8 critical | 3.3% | 2022-10-25 |
| CVE-2019-13025 | Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation. The attacker can send a… | In your normal cycle | 9.8 critical | 3.3% | 2019-10-02 |
| CVE-2016-3609 | Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect… | In your normal cycle | 9.0 critical | 3.3% | 2016-07-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt