CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,164 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,038 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-92397 | A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sg… | In your normal cycle | 9.1 critical | 3.2% | 2026-09-16 |
| CVE-2026-92398 | A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admi… | In your normal cycle | 9.1 critical | 3.2% | 2026-09-16 |
| CVE-2013-1400 | Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via… | In your normal cycle | 9.8 critical | 3.2% | 2020-02-13 |
| CVE-2017-11495 | PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternative… | In your normal cycle | 9.8 critical | 3.2% | 2017-07-20 |
| CVE-2026-18963 | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red… | In your normal cycle | 9.1 critical | 3.2% | 2026-08-18 |
| CVE-2018-17607 | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properti… | In your normal cycle | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17608 | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properti… | In your normal cycle | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17609 | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properti… | In your normal cycle | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17610 | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properti… | In your normal cycle | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17611 | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properti… | In your normal cycle | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2017-14624 | ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function PostscriptDelegateMessage in coders/ps.c. | In your normal cycle | 9.8 critical | 3.2% | 2017-09-21 |
| CVE-2017-14625 | ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_output_create in coders/sixel.c. | In your normal cycle | 9.8 critical | 3.2% | 2017-09-21 |
| CVE-2018-1999019 | Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.php… | In your normal cycle | 9.8 critical | 3.2% | 2018-07-23 |
| CVE-2023-31746 | There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulne… | In your normal cycle | 9.8 critical | 3.2% | 2023-06-14 |
| CVE-2022-21241 | Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrary script or an arbitrary OS co… | In your normal cycle | 9.6 critical | 3.2% | 2022-02-08 |
| CVE-2024-23628 | A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vul… | In your normal cycle | 9.0 critical | 3.2% | 2024-01-26 |
| CVE-2016-7922 | The AH parser in tcpdump before 4.9.0 has a buffer overflow in print-ah.c:ah_print(). | In your normal cycle | 9.8 critical | 3.2% | 2017-01-28 |
| CVE-2020-25197 | A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06… | In your normal cycle | 9.8 critical | 3.2% | 2022-03-18 |
| CVE-2020-17528 | Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt m… | In your normal cycle | 9.1 critical | 3.2% | 2020-12-09 |
| CVE-2024-12252 | The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remote_update AJAX action in all v… | In your normal cycle | 9.8 critical | 3.2% | 2025-01-07 |
| CVE-2022-37125 | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost. | In your normal cycle | 9.8 critical | 3.2% | 2022-08-31 |
| CVE-2017-12706 | A stack-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulner… | In your normal cycle | 9.8 critical | 3.2% | 2017-08-30 |
| CVE-2017-5226 | When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push character… | In your normal cycle | 10.0 critical | 3.2% | 2017-03-29 |
| CVE-2020-23639 | A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arbi… | In your normal cycle | 9.8 critical | 3.2% | 2020-11-02 |
| CVE-2021-31272 | SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command e… | In your normal cycle | 9.8 critical | 3.2% | 2021-06-18 |
| CVE-2021-45835 | The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents… | In your normal cycle | 9.8 critical | 3.2% | 2022-03-18 |
| CVE-2026-89010 | WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows… | In your normal cycle | 9.8 critical | 3.2% | 2026-09-11 |
| CVE-2026-71944 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /b… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
| CVE-2026-71945 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /b… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
| CVE-2026-71946 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /b… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt