CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,038 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-7072 | A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24. | In your normal cycle | 9.8 critical | 3.1% | 2018-08-06 |
| CVE-2016-7985 | The CALM FAST parser in tcpdump before 4.9.0 has a buffer overflow in print-calm-fast.c:calm_fast_print(). | In your normal cycle | 9.8 critical | 3.1% | 2017-01-28 |
| CVE-2016-8574 | The FRF.15 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:frf15_print(). | In your normal cycle | 9.8 critical | 3.1% | 2017-01-28 |
| CVE-2017-16743 | An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32… | In your normal cycle | 9.8 critical | 3.1% | 2018-01-12 |
| CVE-2021-46386 | File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsof… | In your normal cycle | 9.8 critical | 3.1% | 2022-01-26 |
| CVE-2023-48692 | Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote c… | In your normal cycle | 9.0 critical | 3.1% | 2023-12-05 |
| CVE-2016-6530 | Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain a… | In your normal cycle | 9.8 critical | 3.1% | 2016-09-21 |
| CVE-2017-1000444 | Eleix Openhacker version 0.1.47 is vulnerable to an SQL injection in the account registration and login component resulting in information disclosure… | In your normal cycle | 9.8 critical | 3.1% | 2018-01-02 |
| CVE-2017-7640 | QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the… | In your normal cycle | 9.8 critical | 3.1% | 2018-03-08 |
| CVE-2019-17362 | In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequen… | In your normal cycle | 9.1 critical | 3.1% | 2019-10-09 |
| CVE-2020-10640 | Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code executi… | In your normal cycle | 10.0 critical | 3.1% | 2022-02-24 |
| CVE-2019-17455 | Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations,… | In your normal cycle | 9.8 critical | 3.1% | 2019-10-10 |
| CVE-2022-31794 | An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestT… | In your normal cycle | 9.8 critical | 3.1% | 2022-06-20 |
| CVE-2022-31795 | An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_fin… | In your normal cycle | 9.8 critical | 3.1% | 2022-06-20 |
| CVE-2024-13979 | A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL comma… | In your normal cycle | 9.8 critical | 3.1% | 2025-08-27 |
| CVE-2020-28279 | Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of service and may lead to remote… | In your normal cycle | 9.8 critical | 3.1% | 2020-12-29 |
| CVE-2017-10934 | All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (AC… | In your normal cycle | 9.8 critical | 3.1% | 2018-07-25 |
| CVE-2017-7758 | An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vul… | In your normal cycle | 9.1 critical | 3.1% | 2018-06-11 |
| CVE-2019-10985 | In WebAccess/SCADA, Versions 8.3.5 and prior, a path traversal vulnerability is caused by a lack of proper validation of a user-supplied path prior to… | In your normal cycle | 9.1 critical | 3.1% | 2019-06-28 |
| CVE-2019-9201 | Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as de… | In your normal cycle | 9.8 critical | 3.1% | 2019-02-26 |
| CVE-2020-24987 | Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authenticatio… | In your normal cycle | 9.8 critical | 3.1% | 2020-09-04 |
| CVE-2021-37599 | The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthe… | In your normal cycle | 9.8 critical | 3.1% | 2021-08-12 |
| CVE-2021-34084 | OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via t… | In your normal cycle | 9.8 critical | 3.1% | 2022-06-02 |
| CVE-2025-27407 | graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, a… | In your normal cycle | 9.0 critical | 3.1% | 2025-03-12 |
| CVE-2023-30869 | Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads:… | In your normal cycle | 9.8 critical | 3.1% | 2023-05-02 |
| CVE-2016-2359 | Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously mak… | In your normal cycle | 9.8 critical | 3.1% | 2019-10-25 |
| CVE-2018-5440 | A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server. Specifically: all Microsoft Windows (also WinCE) based CODESYS web… | In your normal cycle | 9.8 critical | 3.1% | 2018-02-15 |
| CVE-2020-25749 | The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full… | In your normal cycle | 9.8 critical | 3.1% | 2020-09-25 |
| CVE-2020-36326 | PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE… | In your normal cycle | 9.8 critical | 3.1% | 2021-04-28 |
| CVE-2017-9785 | Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie. | In your normal cycle | 9.8 critical | 3.1% | 2017-07-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt