CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,145 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
37,037 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-7153 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMiniuiHomeInfoShow of the file /c… | In your normal cycle | 9.8 critical | 3.3% | 2026-04-27 |
| CVE-2026-7154 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi… | In your normal cycle | 9.8 critical | 3.3% | 2026-04-27 |
| CVE-2026-7155 | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPasswordCfg of the file /cgi-bin… | In your normal cycle | 9.8 critical | 3.3% | 2026-04-27 |
| CVE-2026-7156 | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the comp… | In your normal cycle | 9.8 critical | 3.3% | 2026-04-27 |
| CVE-2026-7202 | A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of… | In your normal cycle | 9.8 critical | 3.3% | 2026-04-28 |
| CVE-2026-7203 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cste… | In your normal cycle | 9.8 critical | 3.3% | 2026-04-28 |
| CVE-2026-7204 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.… | In your normal cycle | 9.8 critical | 3.3% | 2026-04-28 |
| CVE-2026-7240 | A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setVpnAccountCfg of the file /cgi-bin/… | In your normal cycle | 9.8 critical | 3.3% | 2026-04-28 |
| CVE-2026-7241 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of… | In your normal cycle | 9.8 critical | 3.3% | 2026-04-28 |
| CVE-2026-7242 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi… | In your normal cycle | 9.8 critical | 3.3% | 2026-04-28 |
| CVE-2026-7243 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi.… | In your normal cycle | 9.8 critical | 3.3% | 2026-04-28 |
| CVE-2026-7244 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiFiEasyGuestCfg of the file /cgi… | In your normal cycle | 9.8 critical | 3.3% | 2026-04-28 |
| CVE-2026-7538 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cgi… | In your normal cycle | 9.8 critical | 3.3% | 2026-05-01 |
| CVE-2026-7823 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi… | In your normal cycle | 9.8 critical | 3.3% | 2026-05-05 |
| CVE-2017-5373 | Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that wit… | In your normal cycle | 9.8 critical | 3.3% | 2018-06-11 |
| CVE-2021-36163 | In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reques… | In your normal cycle | 9.8 critical | 3.3% | 2021-09-07 |
| CVE-2019-18960 | Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes. | In your normal cycle | 9.8 critical | 3.3% | 2019-12-11 |
| CVE-2018-3784 | A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization. | In your normal cycle | 9.8 critical | 3.3% | 2018-08-17 |
| CVE-2019-1010022 | GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vect… | In your normal cycle | 9.8 critical | 3.2% | 2019-07-15 |
| CVE-2023-54391 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows una… | In your normal cycle | 9.8 critical | 3.2% | 2026-09-01 |
| CVE-2019-11930 | An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions… | In your normal cycle | 9.8 critical | 3.2% | 2019-12-04 |
| CVE-2026-1405 | The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_… | In your normal cycle | 9.8 critical | 3.2% | 2026-02-19 |
| CVE-2022-33193 | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z… | In your normal cycle | 10.0 critical | 3.2% | 2022-10-25 |
| CVE-2022-33194 | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z… | In your normal cycle | 10.0 critical | 3.2% | 2022-10-25 |
| CVE-2018-9356 | In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no addi… | In your normal cycle | 9.8 critical | 3.2% | 2018-11-06 |
| CVE-2017-5428 | An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extens… | In your normal cycle | 9.8 critical | 3.2% | 2018-06-11 |
| CVE-2018-17922 | Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without… | In your normal cycle | 9.8 critical | 3.2% | 2018-11-02 |
| CVE-2021-27647 | Out-of-bounds Read vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to exe… | In your normal cycle | 9.8 critical | 3.2% | 2021-03-12 |
| CVE-2018-5435 | The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Pl… | In your normal cycle | 9.6 critical | 3.2% | 2018-06-27 |
| CVE-2021-21524 | Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerability. A remote unauthenticated… | In your normal cycle | 9.8 critical | 3.2% | 2021-04-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt