CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,145 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
37,037 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-1581 | A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access… | In your normal cycle | 9.8 critical | 3.2% | 2019-08-23 |
| CVE-2019-8527 | A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A remote… | In your normal cycle | 9.1 critical | 3.2% | 2019-12-18 |
| CVE-2017-13026 | The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c, several functions. | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13027 | The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_mgmt_addr_tlv_print(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13031 | The IPv6 fragmentation header parser in tcpdump before 4.9.2 has a buffer over-read in print-frag6.c:frag6_print(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13032 | The RADIUS parser in tcpdump before 4.9.2 has a buffer over-read in print-radius.c:print_attr_string(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13034 | The PGM parser in tcpdump before 4.9.2 has a buffer over-read in print-pgm.c:pgm_print(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13042 | The HNCP parser in tcpdump before 4.9.2 has a buffer over-read in print-hncp.c:dhcpv6_print(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13043 | The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:decode_multicast_vpn(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13046 | The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13047 | The ISO ES-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:esis_print(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13048 | The RSVP parser in tcpdump before 4.9.2 has a buffer over-read in print-rsvp.c:rsvp_obj_print(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13051 | The RSVP parser in tcpdump before 4.9.2 has a buffer over-read in print-rsvp.c:rsvp_obj_print(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13053 | The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:decode_rt_routing_info(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13054 | The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_private_8023_print(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13055 | The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print_is_reach_subtlv(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13688 | The OLSR parser in tcpdump before 4.9.2 has a buffer over-read in print-olsr.c:olsr_print(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2017-13689 | The IKEv1 parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:ikev1_id_print(). | In your normal cycle | 9.8 critical | 3.2% | 2017-09-14 |
| CVE-2020-27304 | The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file u… | In your normal cycle | 9.8 critical | 3.2% | 2021-10-21 |
| CVE-2017-1000235 | I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised. | In your normal cycle | 9.8 critical | 3.2% | 2017-11-17 |
| CVE-2022-1664 | Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal… | In your normal cycle | 9.8 critical | 3.2% | 2022-05-26 |
| CVE-2023-37895 | Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (inc… | In your normal cycle | 9.8 critical | 3.2% | 2023-07-25 |
| CVE-2020-28333 | Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not us… | In your normal cycle | 9.8 critical | 3.2% | 2020-11-24 |
| CVE-2022-40083 | Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by… | In your normal cycle | 9.6 critical | 3.2% | 2022-09-28 |
| CVE-2017-6519 | avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows r… | In your normal cycle | 9.1 critical | 3.2% | 2017-05-01 |
| CVE-2018-16518 | A directory traversal vulnerability with remote code execution in Prim'X Zed! FREE through 1.0 build 186 and Zed! Limited Edition through 6.1 build 22… | In your normal cycle | 9.8 critical | 3.2% | 2018-09-05 |
| CVE-2015-0855 | The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file… | In your normal cycle | 9.8 critical | 3.2% | 2017-03-23 |
| CVE-2015-8212 | CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted a… | In your normal cycle | 9.8 critical | 3.2% | 2017-01-19 |
| CVE-2020-6017 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when co… | In your normal cycle | 9.8 critical | 3.2% | 2020-12-03 |
| CVE-2020-6018 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decrypt() when… | In your normal cycle | 9.8 critical | 3.2% | 2020-12-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt