CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,166 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,038 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-71947 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /b… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
| CVE-2026-71948 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /b… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
| CVE-2026-71949 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /b… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
| CVE-2026-71950 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /b… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
| CVE-2026-71951 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /b… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
| CVE-2026-71952 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /b… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
| CVE-2026-71953 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /b… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
| CVE-2026-71954 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /b… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
| CVE-2026-71955 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/f… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
| CVE-2026-71956 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi i… | In your normal cycle | 9.8 critical | 3.2% | 2026-08-08 |
| CVE-2017-5380 | A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR <… | In your normal cycle | 9.8 critical | 3.2% | 2018-06-11 |
| CVE-2018-14349 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message. | In your normal cycle | 9.8 critical | 3.2% | 2018-07-17 |
| CVE-2018-14351 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size. | In your normal cycle | 9.8 critical | 3.2% | 2018-07-17 |
| CVE-2018-14356 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID. | In your normal cycle | 9.8 critical | 3.2% | 2018-07-17 |
| CVE-2017-1789 | IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 137… | In your normal cycle | 9.8 critical | 3.2% | 2018-03-22 |
| CVE-2019-17559 | There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgra… | In your normal cycle | 9.8 critical | 3.2% | 2020-03-23 |
| CVE-2019-17565 | There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upg… | In your normal cycle | 9.8 critical | 3.2% | 2020-03-23 |
| CVE-2024-27173 | Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerabi… | In your normal cycle | 9.8 critical | 3.2% | 2024-06-14 |
| CVE-2021-25311 | condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a… | In your normal cycle | 9.9 critical | 3.2% | 2021-01-27 |
| CVE-2017-7625 | In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execut… | In your normal cycle | 9.8 critical | 3.2% | 2017-04-10 |
| CVE-2020-5499 | Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same. | In your normal cycle | 9.8 critical | 3.2% | 2020-01-04 |
| CVE-2020-7561 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide ran… | In your normal cycle | 9.8 critical | 3.2% | 2020-11-19 |
| CVE-2016-5239 | The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecif… | In your normal cycle | 9.8 critical | 3.2% | 2017-03-15 |
| CVE-2021-43722 | D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header ont… | In your normal cycle | 9.8 critical | 3.2% | 2022-03-31 |
| CVE-2022-21141 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does… | In your normal cycle | 10.0 critical | 3.2% | 2022-02-18 |
| CVE-2018-1000854 | esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('… | In your normal cycle | 9.8 critical | 3.2% | 2018-12-20 |
| CVE-2017-9736 | SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote c… | In your normal cycle | 9.8 critical | 3.2% | 2017-06-17 |
| CVE-2022-48174 | There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be ex… | In your normal cycle | 9.8 critical | 3.2% | 2023-08-22 |
| CVE-2016-9679 | Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer. | In your normal cycle | 9.8 critical | 3.2% | 2017-01-18 |
| CVE-2020-24698 | An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might… | In your normal cycle | 9.8 critical | 3.2% | 2020-10-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt