CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,240 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,039 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-24640 | There is a vulnerability caused by insufficient input validation that allows for arbitrary command execution in a containerized environment within Air… | In your normal cycle | 9.8 critical | 3% | 2021-01-15 |
| CVE-2021-24240 | The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leadin… | In your normal cycle | 9.8 critical | 3% | 2021-04-22 |
| CVE-2016-5792 | SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified fields. | In your normal cycle | 9.8 critical | 3% | 2016-08-08 |
| CVE-2026-36576 | An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbi… | In your normal cycle | 9.8 critical | 3% | 2026-06-03 |
| CVE-2019-19896 | In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP… | In your normal cycle | 9.9 critical | 3% | 2020-01-23 |
| CVE-2024-36858 | An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading… | In your normal cycle | 9.8 critical | 3% | 2024-06-04 |
| CVE-2026-27476 | RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 w… | In your normal cycle | 9.8 critical | 3% | 2026-02-19 |
| CVE-2019-19513 | The BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability. An attacker may exploit this… | In your normal cycle | 9.8 critical | 3% | 2020-10-16 |
| CVE-2021-26622 | An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote… | In your normal cycle | 9.6 critical | 3% | 2022-03-25 |
| CVE-2017-4990 | In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of t… | In your normal cycle | 9.8 critical | 3% | 2017-06-21 |
| CVE-2017-14377 | EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Bui… | In your normal cycle | 9.8 critical | 3% | 2017-11-29 |
| CVE-2020-28464 | This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine. | In your normal cycle | 9.8 critical | 3% | 2021-01-04 |
| CVE-2026-49468 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy… | In your normal cycle | 9.8 critical | 3% | 2026-06-22 |
| CVE-2019-3774 | Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML… | In your normal cycle | 9.8 critical | 3% | 2019-01-18 |
| CVE-2022-20712 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | In your normal cycle | 10.0 critical | 3% | 2022-02-10 |
| CVE-2020-35184 | The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affe… | In your normal cycle | 9.8 critical | 3% | 2020-12-17 |
| CVE-2026-26478 | A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially craft… | In your normal cycle | 9.8 critical | 3% | 2026-03-04 |
| CVE-2020-9027 | ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The NTP-2 device is also affected. | In your normal cycle | 9.8 critical | 3% | 2020-02-17 |
| CVE-2018-19971 | JFrog Artifactory Pro 6.5.9 has Incorrect Access Control. | In your normal cycle | 9.8 critical | 3% | 2019-04-16 |
| CVE-2020-12013 | A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi Ele… | In your normal cycle | 9.1 critical | 3% | 2020-07-16 |
| CVE-2024-32026 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_gui.py`. This vulnerability is… | In your normal cycle | 9.1 critical | 3% | 2024-04-16 |
| CVE-2024-32027 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetune_gui.py` This vulnerability i… | In your normal cycle | 9.1 critical | 3% | 2024-04-16 |
| CVE-2019-3888 | A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors… | In your normal cycle | 9.8 critical | 3% | 2019-06-12 |
| CVE-2018-5099 | A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, res… | In your normal cycle | 9.8 critical | 3% | 2018-06-11 |
| CVE-2018-5103 | A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitabl… | In your normal cycle | 9.8 critical | 3% | 2018-06-11 |
| CVE-2020-25159 | 499ES EtherNet/IP (ENIP) Adaptor Source Code is vulnerable to a stack-based buffer overflow, which may allow an attacker to send a specially crafted p… | In your normal cycle | 9.8 critical | 3% | 2020-11-24 |
| CVE-2026-43641 | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unau… | In your normal cycle | 9.8 critical | 3% | 2026-09-22 |
| CVE-2017-13707 | Privilege escalation in Replibit Backup Manager earlier than version 2017.08.04 allows attackers to gain root privileges via sudo command execution. T… | In your normal cycle | 9.8 critical | 3% | 2017-08-27 |
| CVE-2017-5401 | A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable… | In your normal cycle | 9.8 critical | 3% | 2018-06-11 |
| CVE-2018-7485 | The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause… | In your normal cycle | 9.8 critical | 3% | 2018-02-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt