CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,237 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,039 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-28360 | Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker c… | In your normal cycle | 9.8 critical | 3.1% | 2020-11-23 |
| CVE-2017-2142 | Buffer overflow in WN-G300R3 firmware Ver.1.03 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. | In your normal cycle | 9.8 critical | 3.1% | 2017-04-28 |
| CVE-2020-17467 | An issue was discovered in FNET through 4.6.4. The code for processing the hostname from an LLMNR request doesn't check for '\0' termination. Therefor… | In your normal cycle | 9.1 critical | 3.1% | 2020-12-11 |
| CVE-2016-10764 | In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash() function. There are CQSPI_MA… | In your normal cycle | 9.8 critical | 3.1% | 2019-07-27 |
| CVE-2019-15741 | An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation | In your normal cycle | 9.8 critical | 3.1% | 2019-09-16 |
| CVE-2018-10771 | Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (applic… | In your normal cycle | 9.8 critical | 3.1% | 2018-05-07 |
| CVE-2021-22201 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server… | In your normal cycle | 9.6 critical | 3.1% | 2021-04-02 |
| CVE-2021-43523 | In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo… | In your normal cycle | 9.6 critical | 3.1% | 2021-11-10 |
| CVE-2022-23806 | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that i… | In your normal cycle | 9.1 critical | 3.1% | 2022-02-11 |
| CVE-2020-7055 | An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to exec… | In your normal cycle | 9.9 critical | 3.1% | 2020-04-22 |
| CVE-2018-5098 | A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentia… | In your normal cycle | 9.8 critical | 3.1% | 2018-06-11 |
| CVE-2022-44621 | Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request. | In your normal cycle | 9.8 critical | 3.1% | 2022-12-30 |
| CVE-2021-33963 | China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter… | In your normal cycle | 9.8 critical | 3.1% | 2022-01-15 |
| CVE-2020-28276 | Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code… | In your normal cycle | 9.8 critical | 3.1% | 2020-12-29 |
| CVE-2020-28277 | Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code exec… | In your normal cycle | 9.8 critical | 3.1% | 2020-12-29 |
| CVE-2020-28278 | Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code e… | In your normal cycle | 9.8 critical | 3.1% | 2020-12-29 |
| CVE-2020-28280 | Prototype pollution vulnerability in 'predefine' versions 0.0.0 through 0.1.2 allows an attacker to cause a denial of service and may lead to remote c… | In your normal cycle | 9.8 critical | 3.1% | 2020-12-29 |
| CVE-2018-1999010 | FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can resul… | In your normal cycle | 9.8 critical | 3.1% | 2018-07-23 |
| CVE-2017-8248 | A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation… | In your normal cycle | 9.8 critical | 3.1% | 2017-08-16 |
| CVE-2021-40883 | A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins. | In your normal cycle | 9.8 critical | 3.1% | 2021-12-14 |
| CVE-2018-14473 | OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sendin… | In your normal cycle | 9.1 critical | 3.1% | 2018-08-04 |
| CVE-2016-9678 | Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors. | In your normal cycle | 9.8 critical | 3.1% | 2017-01-18 |
| CVE-2021-45742 | TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows at… | In your normal cycle | 9.8 critical | 3.1% | 2022-02-04 |
| CVE-2020-11966 | In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The… | In your normal cycle | 9.8 critical | 3.1% | 2020-04-21 |
| CVE-2019-11353 | The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute utilities b… | In your normal cycle | 9.8 critical | 3.1% | 2019-05-09 |
| CVE-2021-39383 | DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java. | In your normal cycle | 9.8 critical | 3.1% | 2022-03-20 |
| CVE-2019-9025 | An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_… | In your normal cycle | 9.8 critical | 3.1% | 2019-02-22 |
| CVE-2020-8432 | In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what… | In your normal cycle | 9.8 critical | 3.1% | 2020-01-29 |
| CVE-2021-35973 | NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated att… | In your normal cycle | 9.8 critical | 3.1% | 2021-06-30 |
| CVE-2020-5616 | [Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0,… | In your normal cycle | 9.8 critical | 3.1% | 2020-08-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt