CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,166 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,038 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-38428 | An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not c… | In your normal cycle | 9.1 critical | 3.2% | 2023-07-18 |
| CVE-2025-45854 | /server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams. | In your normal cycle | 10.0 critical | 3.2% | 2025-06-03 |
| CVE-2021-45040 | The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the uplo… | In your normal cycle | 9.8 critical | 3.2% | 2022-03-17 |
| CVE-2021-31226 | An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parses the HTTP POST request, due t… | In your normal cycle | 9.8 critical | 3.2% | 2021-08-19 |
| CVE-2021-38173 | Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized… | In your normal cycle | 9.8 critical | 3.2% | 2021-08-07 |
| CVE-2018-2930 | Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). Supported versions that are a… | In your normal cycle | 9.8 critical | 3.2% | 2018-07-18 |
| CVE-2021-28132 | LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows… | In your normal cycle | 9.8 critical | 3.2% | 2021-03-11 |
| CVE-2019-19782 | The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server. | In your normal cycle | 9.8 critical | 3.2% | 2019-12-13 |
| CVE-2026-79698 | A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WI… | In your normal cycle | 9.9 critical | 3.2% | 2026-09-07 |
| CVE-2023-2645 | A vulnerability, which was classified as critical, was found in USR USR-G806 1.0.41. Affected is an unknown function of the component Web Management P… | In your normal cycle | 9.8 critical | 3.2% | 2023-05-11 |
| CVE-2024-1207 | The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versi… | In your normal cycle | 9.8 critical | 3.2% | 2024-02-08 |
| CVE-2020-13451 | An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuratio… | In your normal cycle | 9.8 critical | 3.2% | 2021-01-07 |
| CVE-2023-5974 | The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter. | In your normal cycle | 9.8 critical | 3.2% | 2023-11-27 |
| CVE-2020-8147 | Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code exe… | In your normal cycle | 9.8 critical | 3.1% | 2020-04-03 |
| CVE-2020-25094 | LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSoc… | In your normal cycle | 9.8 critical | 3.1% | 2020-12-17 |
| CVE-2017-18858 | Certain NETGEAR devices are affected by command execution. This affects M4200-10MG-POE+ 12.0.2.11 and earlier, M4300-28G 12.0.2.11 and earlier, M4300-… | In your normal cycle | 9.8 critical | 3.1% | 2020-04-28 |
| CVE-2017-12236 | A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, re… | In your normal cycle | 9.8 critical | 3.1% | 2017-09-29 |
| CVE-2017-12758 | https://www.joomlaextensions.co.in/ Joomla! Component Appointment 1.1 is affected by: SQL Injection. The impact is: Code execution (remote). The compo… | In your normal cycle | 9.8 critical | 3.1% | 2019-05-09 |
| CVE-2019-15524 | CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote c… | In your normal cycle | 9.8 critical | 3.1% | 2019-08-26 |
| CVE-2023-28323 | A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit… | In your normal cycle | 9.8 critical | 3.1% | 2023-07-01 |
| CVE-2021-46461 | njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njs_vmcode_typeof in /src/njs_vmcode.c. | In your normal cycle | 9.8 critical | 3.1% | 2022-02-14 |
| CVE-2019-14363 | A stack-based buffer overflow in the upnpd binary running on NETGEAR WNDR3400v3 routers with firmware version 1.0.1.18_1.0.63 allows an attacker to re… | In your normal cycle | 9.8 critical | 3.1% | 2019-07-28 |
| CVE-2021-30805 | A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina,… | In your normal cycle | 9.8 critical | 3.1% | 2021-09-08 |
| CVE-2018-12376 | Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough… | In your normal cycle | 9.8 critical | 3.1% | 2018-10-18 |
| CVE-2020-7730 | The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param. | In your normal cycle | 9.8 critical | 3.1% | 2020-09-04 |
| CVE-2017-7753 | An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects T… | In your normal cycle | 9.1 critical | 3.1% | 2018-06-11 |
| CVE-2015-5959 | Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.l… | In your normal cycle | 9.8 critical | 3.1% | 2017-09-06 |
| CVE-2012-6611 | An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Pla… | In your normal cycle | 9.8 critical | 3.1% | 2020-02-10 |
| CVE-2017-10285 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u16… | In your normal cycle | 9.6 critical | 3.1% | 2017-10-19 |
| CVE-2019-8265 | UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of SETPIXELS macro in VNC client code, which ca… | In your normal cycle | 9.8 critical | 3.1% | 2019-03-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt