CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,932 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
37,037 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-17434 | The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in… | In your normal cycle | 9.8 critical | 3.3% | 2017-12-06 |
| CVE-2021-30228 | The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell… | In your normal cycle | 9.8 critical | 3.3% | 2021-04-29 |
| CVE-2021-30230 | The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shel… | In your normal cycle | 9.8 critical | 3.3% | 2021-04-29 |
| CVE-2021-30231 | The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metach… | In your normal cycle | 9.8 critical | 3.3% | 2021-04-29 |
| CVE-2021-30232 | The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell m… | In your normal cycle | 9.8 critical | 3.3% | 2021-04-29 |
| CVE-2021-30233 | The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell meta… | In your normal cycle | 9.8 critical | 3.3% | 2021-04-29 |
| CVE-2021-30234 | The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell me… | In your normal cycle | 9.8 critical | 3.3% | 2021-04-29 |
| CVE-2016-6223 | The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash… | In your normal cycle | 9.1 critical | 3.3% | 2017-01-23 |
| CVE-2017-18201 | An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c. | In your normal cycle | 9.8 critical | 3.3% | 2018-02-26 |
| CVE-2020-11967 | In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note… | In your normal cycle | 9.8 critical | 3.3% | 2020-04-21 |
| CVE-2025-59361 | The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthen… | In your normal cycle | 9.8 critical | 3.3% | 2025-09-15 |
| CVE-2021-21025 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the product layout updates. Su… | In your normal cycle | 9.1 critical | 3.3% | 2021-02-11 |
| CVE-2021-34423 | A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Cl… | In your normal cycle | 9.8 critical | 3.3% | 2021-11-24 |
| CVE-2018-6444 | A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnerab… | In your normal cycle | 9.8 critical | 3.3% | 2019-01-22 |
| CVE-2016-4734 | WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (me… | In your normal cycle | 9.6 critical | 3.3% | 2016-09-25 |
| CVE-2020-13753 | The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEW… | In your normal cycle | 10.0 critical | 3.3% | 2020-07-14 |
| CVE-2016-5081 | ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET sessio… | In your normal cycle | 9.8 critical | 3.3% | 2016-08-24 |
| CVE-2016-6532 | DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this pas… | In your normal cycle | 9.8 critical | 3.3% | 2016-09-24 |
| CVE-2019-6552 | Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplie… | In your normal cycle | 9.8 critical | 3.3% | 2019-04-05 |
| CVE-2022-25390 | DCN Firewall DCME-520 was discovered to contain a remote command execution (RCE) vulnerability via the host parameter in the file /system/tool/ping.ph… | In your normal cycle | 9.8 critical | 3.3% | 2022-03-18 |
| CVE-2021-37161 | A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare Nexus Panel, operated by released versions o… | In your normal cycle | 9.8 critical | 3.3% | 2021-08-02 |
| CVE-2021-37162 | A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus… | In your normal cycle | 9.8 critical | 3.3% | 2021-08-02 |
| CVE-2021-37165 | A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus… | In your normal cycle | 9.8 critical | 3.3% | 2021-08-02 |
| CVE-2017-9521 | The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v3… | In your normal cycle | 9.8 critical | 3.3% | 2017-07-31 |
| CVE-2018-12407 | A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuf… | In your normal cycle | 9.8 critical | 3.3% | 2019-02-28 |
| CVE-2019-12549 | WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of… | In your normal cycle | 9.8 critical | 3.3% | 2019-06-17 |
| CVE-2018-7096 | A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to a… | In your normal cycle | 9.8 critical | 3.3% | 2018-08-14 |
| CVE-2022-25809 | Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices… | In your normal cycle | 9.8 critical | 3.3% | 2022-02-24 |
| CVE-2018-5154 | A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable… | In your normal cycle | 9.8 critical | 3.3% | 2018-06-11 |
| CVE-2019-16734 | Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitra… | In your normal cycle | 9.8 critical | 3.3% | 2019-12-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt