CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,237 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,039 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-8241 | XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return v… | In your normal cycle | 9.8 critical | 3.1% | 2016-12-14 |
| CVE-2016-0733 | The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to byp… | In your normal cycle | 9.8 critical | 3.1% | 2016-04-12 |
| CVE-2026-19747 | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the fun… | In your normal cycle | 9.8 critical | 3.1% | 2026-08-13 |
| CVE-2016-5405 | 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6… | In your normal cycle | 9.8 critical | 3.1% | 2017-06-08 |
| CVE-2018-5299 | A stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect Secure (PCS) before 8.3R4 and Pulse Policy Secure (… | In your normal cycle | 9.8 critical | 3.1% | 2018-01-16 |
| CVE-2019-13143 | An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name… | In your normal cycle | 9.8 critical | 3.1% | 2019-08-06 |
| CVE-2019-17212 | Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0. The CoAP parser is responsible for parsing received CoAP packets. The func… | In your normal cycle | 9.8 critical | 3.1% | 2019-11-05 |
| CVE-2020-9026 | ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected. | In your normal cycle | 9.8 critical | 3.1% | 2020-02-17 |
| CVE-2021-3029 | EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters and an IFS manipulation. The… | In your normal cycle | 9.8 critical | 3.1% | 2021-01-07 |
| CVE-2021-21249 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote c… | In your normal cycle | 9.6 critical | 3.1% | 2021-01-15 |
| CVE-2019-12730 | aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of un… | In your normal cycle | 9.8 critical | 3.1% | 2019-06-04 |
| CVE-2023-31569 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function. | In your normal cycle | 9.8 critical | 3.1% | 2023-06-06 |
| CVE-2018-14786 | Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and prio… | In your normal cycle | 9.4 critical | 3.1% | 2018-08-23 |
| CVE-2021-26476 | EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI. | In your normal cycle | 9.8 critical | 3.1% | 2021-03-01 |
| CVE-2019-17269 | Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field. | In your normal cycle | 9.8 critical | 3.1% | 2019-10-07 |
| CVE-2018-0541 | Buffer overflow in Tiny FTP Daemon Ver0.52d allows an attacker to cause a denial-of-service (DoS) condition or execute arbitrary code via unspecified… | In your normal cycle | 9.8 critical | 3.1% | 2018-03-22 |
| CVE-2021-30793 | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Upd… | In your normal cycle | 9.8 critical | 3.1% | 2021-09-08 |
| CVE-2020-12522 | The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 1… | In your normal cycle | 10.0 critical | 3.1% | 2020-12-17 |
| CVE-2018-14071 | The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input. | In your normal cycle | 9.8 critical | 3.1% | 2018-07-16 |
| CVE-2018-5150 | Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we… | In your normal cycle | 9.8 critical | 3.1% | 2018-06-11 |
| CVE-2016-1000113 | XSS and SQLi in huge IT gallery v1.1.5 for Joomla | In your normal cycle | 9.8 critical | 3.1% | 2016-10-06 |
| CVE-2022-23303 | The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access pa… | In your normal cycle | 9.8 critical | 3.1% | 2022-01-17 |
| CVE-2018-6210 | D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which makes it easier for remote attack… | In your normal cycle | 9.8 critical | 3.1% | 2018-06-19 |
| CVE-2018-6521 | The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. Th… | In your normal cycle | 9.8 critical | 3.1% | 2018-02-02 |
| CVE-2017-0889 | Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attacke… | In your normal cycle | 9.8 critical | 3.1% | 2017-11-13 |
| CVE-2022-21831 | A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments. | In your normal cycle | 9.8 critical | 3.1% | 2022-05-26 |
| CVE-2022-24405 | OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API. | In your normal cycle | 9.8 critical | 3.1% | 2022-07-27 |
| CVE-2026-25070 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpo… | In your normal cycle | 9.8 critical | 3.1% | 2026-03-07 |
| CVE-2017-11519 | passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number ge… | In your normal cycle | 9.8 critical | 3.1% | 2017-07-21 |
| CVE-2017-17671 | vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can… | In your normal cycle | 9.8 critical | 3.1% | 2017-12-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt