CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,922 CVEs
1,739 on KEV
17,301 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
36,992 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-60121 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers… | In your normal cycle | 9.8 critical | 3.3% | 2026-07-13 |
| CVE-2016-5343 | drivers/soc/qcom/qdsp6v2/voice_svc.c in the QDSP6v2 Voice Service driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Androi… | In your normal cycle | 9.8 critical | 3.3% | 2016-10-10 |
| CVE-2019-13478 | The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions. | In your normal cycle | 9.8 critical | 3.3% | 2019-07-09 |
| CVE-2016-9019 | SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9… | In your normal cycle | 9.8 critical | 3.3% | 2017-03-07 |
| CVE-2018-14746 | Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier… | In your normal cycle | 9.8 critical | 3.3% | 2018-11-28 |
| CVE-2020-11939 | In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflow in conc… | In your normal cycle | 9.8 critical | 3.3% | 2020-04-23 |
| CVE-2018-5089 | Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with… | In your normal cycle | 9.8 critical | 3.3% | 2018-06-11 |
| CVE-2017-7826 | Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with… | In your normal cycle | 9.8 critical | 3.3% | 2018-06-11 |
| CVE-2024-38346 | The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and C… | In your normal cycle | 9.8 critical | 3.3% | 2024-07-05 |
| CVE-2024-1403 | In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentica… | In your normal cycle | 10.0 critical | 3.3% | 2024-02-27 |
| CVE-2018-19196 | An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard a… | In your normal cycle | 9.8 critical | 3.3% | 2018-11-12 |
| CVE-2021-25943 | Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code ex… | In your normal cycle | 9.8 critical | 3.3% | 2021-05-14 |
| CVE-2021-25946 | Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote… | In your normal cycle | 9.8 critical | 3.3% | 2021-05-25 |
| CVE-2021-25948 | Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote… | In your normal cycle | 9.8 critical | 3.3% | 2021-06-10 |
| CVE-2021-25949 | Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution. | In your normal cycle | 9.8 critical | 3.3% | 2021-06-10 |
| CVE-2021-28940 | Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command to the cu… | In your normal cycle | 9.8 critical | 3.3% | 2021-04-02 |
| CVE-2023-27637 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a comp… | In your normal cycle | 9.8 critical | 3.3% | 2023-03-22 |
| CVE-2023-27638 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a comp… | In your normal cycle | 9.8 critical | 3.3% | 2023-03-22 |
| CVE-2018-3938 | An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5 firmware… | In your normal cycle | 9.1 critical | 3.3% | 2018-08-14 |
| CVE-2022-20754 | Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (… | In your normal cycle | 9.0 critical | 3.3% | 2022-04-06 |
| CVE-2022-20755 | Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (… | In your normal cycle | 9.0 critical | 3.3% | 2022-04-06 |
| CVE-2019-13547 | Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the functio… | In your normal cycle | 9.8 critical | 3.3% | 2019-10-31 |
| CVE-2026-53576 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v… | In your normal cycle | 10.0 critical | 3.3% | 2026-06-26 |
| CVE-2017-5830 | Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts. | In your normal cycle | 9.8 critical | 3.3% | 2017-03-03 |
| CVE-2020-24636 | A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6… | In your normal cycle | 9.8 critical | 3.3% | 2021-03-29 |
| CVE-2012-2714 | The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via t… | In your normal cycle | 9.8 critical | 3.3% | 2020-01-09 |
| CVE-2022-45796 | Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier… | In your normal cycle | 9.1 critical | 3.3% | 2022-12-16 |
| CVE-2024-6924 | The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action… | In your normal cycle | 9.8 critical | 3.3% | 2024-09-08 |
| CVE-2024-6926 | The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action… | In your normal cycle | 9.8 critical | 3.3% | 2024-09-04 |
| CVE-2024-6928 | The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX act… | In your normal cycle | 9.8 critical | 3.3% | 2024-09-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt