CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,038 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-5183 | Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and… | In your normal cycle | 9.8 critical | 3.1% | 2018-06-11 |
| CVE-2016-0889 | An HTTP servlet in vApp Manager in EMC Unisphere for VMAX Virtual Appliance before 8.2.0 allows remote attackers to write to arbitrary files via a cra… | In your normal cycle | 9.8 critical | 3.1% | 2016-04-15 |
| CVE-2017-5432 | A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. This vulnerability affects Thu… | In your normal cycle | 9.8 critical | 3.1% | 2018-06-11 |
| CVE-2017-5435 | A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This results in a potentially explo… | In your normal cycle | 9.8 critical | 3.1% | 2018-06-11 |
| CVE-2018-21029 | systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent,… | In your normal cycle | 9.8 critical | 3.1% | 2019-10-30 |
| CVE-2022-27260 | An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG f… | In your normal cycle | 9.8 critical | 3.1% | 2022-04-12 |
| CVE-2016-9536 | tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip(). Reported as MSVR 3509… | In your normal cycle | 9.8 critical | 3.1% | 2016-11-22 |
| CVE-2016-9537 | tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Reported as MSVR 35093, MSVR 35096, and MSVR 35097. | In your normal cycle | 9.8 critical | 3.1% | 2016-11-22 |
| CVE-2021-24884 | The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could a… | In your normal cycle | 9.6 critical | 3.1% | 2021-10-25 |
| CVE-2017-12249 | A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker… | In your normal cycle | 9.1 critical | 3.1% | 2017-09-13 |
| CVE-2019-12046 | LemonLDAP::NG -2.0.3 has Incorrect Access Control. | In your normal cycle | 9.8 critical | 3.1% | 2019-05-22 |
| CVE-2020-18879 | Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/… | In your normal cycle | 9.8 critical | 3.1% | 2021-08-20 |
| CVE-2022-27534 | Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data pars… | In your normal cycle | 9.8 critical | 3.1% | 2022-04-01 |
| CVE-2018-18815 | The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server f… | In your normal cycle | 10.0 critical | 3.1% | 2019-03-07 |
| CVE-2007-2020 | Unspecified vulnerability in administration.php in xodagallery allows remote attackers to execute arbitrary code via the cmd parameter. NOTE: CVE disp… | In your normal cycle | 9.8 critical | 3.1% | 2007-04-12 |
| CVE-2017-13000 | The IEEE 802.15.4 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_15_4.c:ieee802_15_4_if_print(). | In your normal cycle | 9.8 critical | 3.1% | 2017-09-14 |
| CVE-2024-52577 | In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerabilit… | In your normal cycle | 9.0 critical | 3.1% | 2025-02-14 |
| CVE-2019-11039 | Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due t… | In your normal cycle | 9.1 critical | 3.1% | 2019-06-19 |
| CVE-2019-0729 | An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict… | In your normal cycle | 9.8 critical | 3.1% | 2019-03-05 |
| CVE-2018-14807 | A stack-based buffer overflow vulnerability in Opto 22 PAC Control Basic and PAC Control Professional versions R10.0a and prior may allow remote code… | In your normal cycle | 9.8 critical | 3.1% | 2018-10-18 |
| CVE-2019-8264 | UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially result in code execution. Thi… | In your normal cycle | 9.8 critical | 3.1% | 2019-03-08 |
| CVE-2022-25081 | TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attack… | In your normal cycle | 9.8 critical | 3.1% | 2022-02-24 |
| CVE-2022-25083 | TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows a… | In your normal cycle | 9.8 critical | 3.1% | 2022-02-24 |
| CVE-2017-10817 | MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server. | In your normal cycle | 9.8 critical | 3.1% | 2017-08-04 |
| CVE-2020-28870 | In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalizatio… | In your normal cycle | 9.8 critical | 3.1% | 2021-02-10 |
| CVE-2024-20418 | A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB)… | In your normal cycle | 10.0 critical | 3.1% | 2024-11-06 |
| CVE-2021-43474 | An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function | In your normal cycle | 9.8 critical | 3.1% | 2022-04-07 |
| CVE-2013-3738 | A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malic… | In your normal cycle | 9.8 critical | 3.1% | 2020-02-17 |
| CVE-2017-1000480 | Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize te… | In your normal cycle | 9.8 critical | 3.1% | 2018-01-03 |
| CVE-2021-39274 | In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user to modify… | In your normal cycle | 9.8 critical | 3.1% | 2021-08-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt