CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,146 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,037 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-1000824 | MegaMek version < v0.45.1 contains a Other/Unknown vulnerability in Object Stream Connection that can result in Disclosure of confidential data, denia… | In your normal cycle | 9.8 critical | 3.2% | 2018-12-20 |
| CVE-2018-1290 | In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL param… | In your normal cycle | 9.8 critical | 3.2% | 2018-04-20 |
| CVE-2026-26830 | pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConv… | In your normal cycle | 9.8 critical | 3.2% | 2026-03-25 |
| CVE-2022-42491 | Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reques… | In your normal cycle | 9.8 critical | 3.2% | 2023-01-26 |
| CVE-2022-42492 | Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reques… | In your normal cycle | 9.8 critical | 3.2% | 2023-01-26 |
| CVE-2018-17126 | CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php. | In your normal cycle | 9.8 critical | 3.2% | 2018-09-17 |
| CVE-2018-6703 | Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers… | In your normal cycle | 9.8 critical | 3.2% | 2018-12-11 |
| CVE-2020-16206 | The affected product is vulnerable to stored cross-site scripting, which may allow an attacker to remotely execute arbitrary code to gain access to se… | In your normal cycle | 9.0 critical | 3.2% | 2020-09-01 |
| CVE-2020-16210 | The affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute arbitrary code and perform actio… | In your normal cycle | 9.0 critical | 3.2% | 2020-09-01 |
| CVE-2018-1000833 | ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, d… | In your normal cycle | 9.8 critical | 3.2% | 2018-12-20 |
| CVE-2018-14494 | Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining tha… | In your normal cycle | 9.8 critical | 3.2% | 2019-07-10 |
| CVE-2022-36756 | DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php. | In your normal cycle | 9.8 critical | 3.2% | 2022-08-28 |
| CVE-2020-29667 | In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve… | In your normal cycle | 9.8 critical | 3.2% | 2020-12-10 |
| CVE-2018-20749 | LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete. | In your normal cycle | 9.8 critical | 3.2% | 2019-01-30 |
| CVE-2017-6350 | An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values fo… | In your normal cycle | 9.8 critical | 3.2% | 2017-02-27 |
| CVE-2021-27817 | A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which… | In your normal cycle | 9.8 critical | 3.2% | 2021-03-15 |
| CVE-2024-44410 | D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function. | In your normal cycle | 9.8 critical | 3.2% | 2024-09-09 |
| CVE-2021-46428 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar paramet… | In your normal cycle | 9.8 critical | 3.2% | 2022-01-27 |
| CVE-2016-10760 | On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter. | In your normal cycle | 9.8 critical | 3.2% | 2019-06-11 |
| CVE-2020-11963 | IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Inj… | In your normal cycle | 9.8 critical | 3.2% | 2020-04-21 |
| CVE-2019-6741 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 Security U… | In your normal cycle | 9.3 critical | 3.2% | 2019-06-03 |
| CVE-2024-23109 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute un… | In your normal cycle | 10.0 critical | 3.2% | 2024-02-05 |
| CVE-2020-5633 | Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Expre… | In your normal cycle | 9.8 critical | 3.2% | 2021-01-13 |
| CVE-2010-20121 | EasyFTP Server versions up to 1.7.0.11 contain a stack-based buffer overflow vulnerability in the FTP command parser. When processing the CWD (Change… | In your normal cycle | 9.8 critical | 3.2% | 2025-08-21 |
| CVE-2022-27263 | An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file. | In your normal cycle | 9.8 critical | 3.2% | 2022-04-12 |
| CVE-2018-1000885 | PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Comm… | In your normal cycle | 9.8 critical | 3.2% | 2018-12-20 |
| CVE-2017-7792 | A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). T… | In your normal cycle | 9.8 critical | 3.2% | 2018-06-11 |
| CVE-2016-2310 | General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firm… | In your normal cycle | 9.8 critical | 3.2% | 2016-06-09 |
| CVE-2019-1580 | Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote,… | In your normal cycle | 9.8 critical | 3.2% | 2019-08-23 |
| CVE-2021-43290 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory… | In your normal cycle | 9.8 critical | 3.2% | 2022-04-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt