CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,069 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
37,037 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-1896 | Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK… | In your normal cycle | 9.8 critical | 3.3% | 2016-01-27 |
| CVE-2019-17544 | libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character. | In your normal cycle | 9.1 critical | 3.3% | 2019-10-14 |
| CVE-2015-8954 | The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypas… | In your normal cycle | 9.8 critical | 3.3% | 2017-03-20 |
| CVE-2018-15556 | The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by… | In your normal cycle | 9.8 critical | 3.3% | 2019-06-27 |
| CVE-2017-20005 | NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an… | In your normal cycle | 9.8 critical | 3.3% | 2021-06-06 |
| CVE-2022-29347 | An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file. | In your normal cycle | 9.8 critical | 3.3% | 2022-05-04 |
| CVE-2023-38951 | ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via… | In your normal cycle | 9.8 critical | 3.3% | 2023-08-03 |
| CVE-2018-20748 | LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete. | In your normal cycle | 9.8 critical | 3.3% | 2019-01-30 |
| CVE-2020-22874 | Integer overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute arbitrary code. | In your normal cycle | 9.8 critical | 3.3% | 2021-07-13 |
| CVE-2020-22875 | Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code. | In your normal cycle | 9.8 critical | 3.3% | 2021-07-13 |
| CVE-2022-23657 | A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2… | In your normal cycle | 10.0 critical | 3.3% | 2022-05-16 |
| CVE-2022-30592 | liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY. | In your normal cycle | 9.8 critical | 3.3% | 2022-05-11 |
| CVE-2018-17890 | NUUO CMS all versions 3.1 and prior, The application uses insecure and outdated software components for functionality, which could allow arbitrary cod… | In your normal cycle | 9.8 critical | 3.3% | 2018-10-12 |
| CVE-2018-2437 | The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can le… | In your normal cycle | 9.1 critical | 3.3% | 2018-07-10 |
| CVE-2018-0487 | ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer ove… | In your normal cycle | 9.8 critical | 3.3% | 2018-02-13 |
| CVE-2016-9157 | A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially… | In your normal cycle | 9.8 critical | 3.3% | 2016-12-05 |
| CVE-2019-5523 | VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and Provider P… | In your normal cycle | 9.8 critical | 3.3% | 2019-04-01 |
| CVE-2020-10569 | SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated… | In your normal cycle | 9.8 critical | 3.3% | 2020-04-21 |
| CVE-2026-82004 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabilit… | In your normal cycle | 10.0 critical | 3.3% | 2026-09-08 |
| CVE-2019-12310 | ExaGrid appliances with firmware version v4.8.1.1044.P50 have a /monitor/data/Upgrade/ directory traversal vulnerability, which allows remote attacker… | In your normal cycle | 9.8 critical | 3.3% | 2019-06-03 |
| CVE-2026-82971 | A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component… | In your normal cycle | 10.0 critical | 3.3% | 2026-08-31 |
| CVE-2026-9384 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecg… | In your normal cycle | 9.8 critical | 3.3% | 2026-05-24 |
| CVE-2026-9385 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.… | In your normal cycle | 9.8 critical | 3.3% | 2026-05-24 |
| CVE-2026-9386 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of th… | In your normal cycle | 9.8 critical | 3.3% | 2026-05-24 |
| CVE-2026-9387 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cs… | In your normal cycle | 9.8 critical | 3.3% | 2026-05-24 |
| CVE-2026-9388 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cstec… | In your normal cycle | 9.8 critical | 3.3% | 2026-05-24 |
| CVE-2026-9404 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the c… | In your normal cycle | 9.8 critical | 3.3% | 2026-05-24 |
| CVE-2026-9405 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cg… | In your normal cycle | 9.8 critical | 3.3% | 2026-05-25 |
| CVE-2026-9406 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the… | In your normal cycle | 9.8 critical | 3.3% | 2026-05-25 |
| CVE-2026-9407 | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setFirewallType of… | In your normal cycle | 9.8 critical | 3.3% | 2026-05-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt