CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,240 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,039 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-16492 | A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prot… | In your normal cycle | 9.8 critical | 3.1% | 2019-02-01 |
| CVE-2019-7564 | An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require… | In your normal cycle | 9.8 critical | 3.1% | 2019-05-07 |
| CVE-2022-24861 | Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code execution vulnerability. JDBC driv… | In your normal cycle | 9.9 critical | 3% | 2022-04-20 |
| CVE-2024-52433 | Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affec… | In your normal cycle | 9.8 critical | 3% | 2024-11-18 |
| CVE-2021-30124 | The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attackers to execute arbitrary code vi… | In your normal cycle | 9.8 critical | 3% | 2021-07-30 |
| CVE-2021-31886 | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACn… | In your normal cycle | 9.8 critical | 3% | 2021-11-09 |
| CVE-2019-15824 | The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass. | In your normal cycle | 9.8 critical | 3% | 2019-08-30 |
| CVE-2019-15825 | The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass. | In your normal cycle | 9.8 critical | 3% | 2019-08-30 |
| CVE-2019-15826 | The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field. | In your normal cycle | 9.8 critical | 3% | 2019-08-30 |
| CVE-2020-10211 | A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to exec… | In your normal cycle | 9.8 critical | 3% | 2020-04-17 |
| CVE-2016-1578 | Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecifi… | In your normal cycle | 9.8 critical | 3% | 2016-05-13 |
| CVE-2019-15897 | beegfs-ctl in ThinkParQ BeeGFS through 7.1.3 allows Authentication Bypass via communication with a BeeGFS metadata server (which is typically not expo… | In your normal cycle | 9.6 critical | 3% | 2019-12-05 |
| CVE-2011-1134 | Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the ima… | In your normal cycle | 9.8 critical | 3% | 2019-11-05 |
| CVE-2026-102792 | A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulati… | In your normal cycle | 9.1 critical | 3% | 2026-09-29 |
| CVE-2015-3442 | Soreco Xpert.Line 3.0 allows local users to spoof users and consequently gain privileges by intercepting a Windows API call. | In your normal cycle | 9.8 critical | 3% | 2017-09-07 |
| CVE-2020-3297 | A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, r… | In your normal cycle | 9.8 critical | 3% | 2020-07-02 |
| CVE-2020-2507 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attacker… | In your normal cycle | 9.8 critical | 3% | 2021-02-03 |
| CVE-2017-12620 | When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects app… | In your normal cycle | 9.8 critical | 3% | 2017-10-03 |
| CVE-2019-9893 | libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might ab… | In your normal cycle | 9.8 critical | 3% | 2019-03-21 |
| CVE-2018-18926 | Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-ma… | In your normal cycle | 9.8 critical | 3% | 2018-11-04 |
| CVE-2019-11399 | An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. OS command injection occurs through the get_… | In your normal cycle | 9.8 critical | 3% | 2019-12-18 |
| CVE-2020-24626 | Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per Use (PPU) U… | In your normal cycle | 9.8 critical | 3% | 2020-09-23 |
| CVE-2017-7860 | Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_… | In your normal cycle | 9.8 critical | 3% | 2017-04-14 |
| CVE-2021-40393 | An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) an… | In your normal cycle | 9.8 critical | 3% | 2021-12-22 |
| CVE-2023-38426 | An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is… | In your normal cycle | 9.1 critical | 3% | 2023-07-18 |
| CVE-2024-9643 | The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web serve… | In your normal cycle | 9.8 critical | 3% | 2025-02-04 |
| CVE-2020-3909 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, wat… | In your normal cycle | 9.8 critical | 3% | 2020-04-01 |
| CVE-2020-10857 | Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution. | In your normal cycle | 9.8 critical | 3% | 2021-02-05 |
| CVE-2021-26275 | The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability onl… | In your normal cycle | 9.8 critical | 3% | 2021-03-19 |
| CVE-2024-52325 | ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection. | In your normal cycle | 9.6 critical | 3% | 2025-01-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt