CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,164 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,038 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-7314 | liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a… | In your normal cycle | 9.8 critical | 3.2% | 2019-02-04 |
| CVE-2016-5670 | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, which makes i… | In your normal cycle | 9.8 critical | 3.2% | 2016-08-03 |
| CVE-2023-35169 | PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Prior to version 5.3.0, an unsan… | In your normal cycle | 9.0 critical | 3.2% | 2023-06-23 |
| CVE-2021-4462 | Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitra… | In your normal cycle | 9.8 critical | 3.2% | 2025-11-10 |
| CVE-2014-2914 | fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to exe… | In your normal cycle | 9.8 critical | 3.2% | 2020-01-28 |
| CVE-2015-8611 | BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, and PEM 12.0.0 before HF1 on the 2000, 4000, 5000, 7000, and 10000 platforms do not p… | In your normal cycle | 9.8 critical | 3.2% | 2016-01-12 |
| CVE-2019-18666 | An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented H… | In your normal cycle | 9.8 critical | 3.2% | 2020-05-15 |
| CVE-2021-0316 | In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code exec… | In your normal cycle | 9.8 critical | 3.2% | 2021-01-11 |
| CVE-2016-6620 | An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The… | In your normal cycle | 9.8 critical | 3.2% | 2016-12-11 |
| CVE-2017-14125 | SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL command… | In your normal cycle | 9.8 critical | 3.2% | 2017-09-25 |
| CVE-2022-25076 | TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows a… | In your normal cycle | 9.8 critical | 3.2% | 2022-02-24 |
| CVE-2022-25078 | TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows… | In your normal cycle | 9.8 critical | 3.2% | 2022-02-24 |
| CVE-2022-25079 | TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows a… | In your normal cycle | 9.8 critical | 3.2% | 2022-02-24 |
| CVE-2022-25080 | TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows atta… | In your normal cycle | 9.8 critical | 3.2% | 2022-02-24 |
| CVE-2021-34552 | Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert functi… | In your normal cycle | 9.8 critical | 3.2% | 2021-07-13 |
| CVE-2020-7720 | The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change rem… | In your normal cycle | 9.8 critical | 3.2% | 2020-09-01 |
| CVE-2022-32292 | In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in receive… | In your normal cycle | 9.8 critical | 3.2% | 2022-08-03 |
| CVE-2019-17206 | Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute… | In your normal cycle | 9.8 critical | 3.2% | 2019-10-05 |
| CVE-2019-9160 | WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a backdoor account allowing a remote attacker to login to the system via SS… | In your normal cycle | 9.8 critical | 3.2% | 2019-04-18 |
| CVE-2020-21585 | Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module. | In your normal cycle | 9.8 critical | 3.2% | 2021-04-02 |
| CVE-2016-7457 | VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via… | In your normal cycle | 10.0 critical | 3.2% | 2016-12-29 |
| CVE-2019-15027 | The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary com… | In your normal cycle | 9.8 critical | 3.2% | 2019-08-14 |
| CVE-2026-2699 | Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to c… | In your normal cycle | 9.8 critical | 3.2% | 2026-04-02 |
| CVE-2024-45337 | Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an aut… | In your normal cycle | 9.1 critical | 3.2% | 2024-12-12 |
| CVE-2020-15690 | In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character. | In your normal cycle | 9.8 critical | 3.2% | 2021-01-30 |
| CVE-2016-5290 | Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with… | In your normal cycle | 9.8 critical | 3.2% | 2018-06-11 |
| CVE-2005-0102 | Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via… | In your normal cycle | 9.8 critical | 3.2% | 2005-01-24 |
| CVE-2021-20716 | Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware V… | In your normal cycle | 9.8 critical | 3.2% | 2021-04-28 |
| CVE-2023-45853 | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment,… | In your normal cycle | 9.8 critical | 3.2% | 2023-10-14 |
| CVE-2026-75094 | A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid… | In your normal cycle | 9.1 critical | 3.2% | 2026-08-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt