CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,146 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,037 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-11682 | A buffer overflow in the SMTP response service in MailCarrier 2.51 allows the attacker to execute arbitrary code remotely via a long HELP command, a r… | In your normal cycle | 9.8 critical | 3.2% | 2019-05-02 |
| CVE-2017-3185 | ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process… | In your normal cycle | 9.8 critical | 3.2% | 2017-12-16 |
| CVE-2021-3520 | There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to… | In your normal cycle | 9.8 critical | 3.2% | 2021-06-02 |
| CVE-2026-41176 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed… | In your normal cycle | 9.8 critical | 3.2% | 2026-04-23 |
| CVE-2019-7321 | Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attac… | In your normal cycle | 9.8 critical | 3.2% | 2019-06-13 |
| CVE-2019-7690 | In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of… | In your normal cycle | 9.8 critical | 3.2% | 2019-05-13 |
| CVE-2021-31915 | In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible. | In your normal cycle | 9.8 critical | 3.2% | 2021-05-11 |
| CVE-2016-4615 | libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchO… | In your normal cycle | 9.8 critical | 3.2% | 2016-07-22 |
| CVE-2016-4616 | libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchO… | In your normal cycle | 9.8 critical | 3.2% | 2016-07-22 |
| CVE-2026-83524 | A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the func… | In your normal cycle | 9.9 critical | 3.2% | 2026-08-31 |
| CVE-2026-83772 | A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode… | In your normal cycle | 9.9 critical | 3.2% | 2026-09-01 |
| CVE-2019-15819 | The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication. | In your normal cycle | 9.8 critical | 3.2% | 2019-08-30 |
| CVE-2020-5653 | Buffer overflow vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First… | In your normal cycle | 9.8 critical | 3.2% | 2020-11-02 |
| CVE-2016-2090 | Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger… | In your normal cycle | 9.8 critical | 3.2% | 2017-01-13 |
| CVE-2016-5843 | Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS… | In your normal cycle | 9.4 critical | 3.2% | 2016-09-17 |
| CVE-2026-9103 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/au… | In your normal cycle | 9.8 critical | 3.2% | 2026-07-17 |
| CVE-2018-12390 | Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of… | In your normal cycle | 9.8 critical | 3.2% | 2019-02-28 |
| CVE-2021-31909 | In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible. | In your normal cycle | 9.8 critical | 3.2% | 2021-05-11 |
| CVE-2015-5609 | Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and delete arbitrary files via a fu… | In your normal cycle | 9.1 critical | 3.2% | 2017-05-23 |
| CVE-2016-2356 | Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password. | In your normal cycle | 9.8 critical | 3.2% | 2019-10-25 |
| CVE-2021-29012 | DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is inval… | In your normal cycle | 9.8 critical | 3.2% | 2021-04-02 |
| CVE-2020-5759 | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can ex… | In your normal cycle | 9.8 critical | 3.2% | 2020-07-17 |
| CVE-2019-8979 | Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled. | In your normal cycle | 9.8 critical | 3.2% | 2019-02-21 |
| CVE-2022-20825 | A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated… | In your normal cycle | 9.8 critical | 3.2% | 2022-06-15 |
| CVE-2022-2023 | Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4. | In your normal cycle | 9.8 critical | 3.2% | 2022-06-20 |
| CVE-2023-36475 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker… | In your normal cycle | 9.8 critical | 3.2% | 2023-06-28 |
| CVE-2026-32917 | OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute a… | In your normal cycle | 9.8 critical | 3.2% | 2026-03-31 |
| CVE-2020-7472 | An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.… | In your normal cycle | 9.8 critical | 3.2% | 2020-11-12 |
| CVE-2018-11325 | An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error… | In your normal cycle | 9.8 critical | 3.2% | 2018-05-22 |
| CVE-2018-12405 | Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of… | In your normal cycle | 9.8 critical | 3.2% | 2019-02-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt