CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,247 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,051 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-8805 | Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a… | In your normal cycle | 9.1 critical | 3% | 2017-10-17 |
| CVE-2021-1459 | A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated… | In your normal cycle | 9.8 critical | 3% | 2021-04-08 |
| CVE-2016-7505 | A buffer overflow vulnerability was observed in divby function of Artifex Software, Inc. MuJS before 8c805b4eb19cf2af689c860b77e6111d2ee439d5. A succe… | In your normal cycle | 9.8 critical | 3% | 2016-10-29 |
| CVE-2023-38036 | A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that c… | In your normal cycle | 9.8 critical | 3% | 2025-07-12 |
| CVE-2017-3272 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE… | In your normal cycle | 9.6 critical | 3% | 2017-01-27 |
| CVE-2016-6545 | Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base6… | In your normal cycle | 9.8 critical | 3% | 2018-07-13 |
| CVE-2022-32585 | A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbi… | In your normal cycle | 9.8 critical | 3% | 2022-06-30 |
| CVE-2015-6323 | The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch… | In your normal cycle | 9.8 critical | 3% | 2016-01-15 |
| CVE-2016-1313 | Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default… | In your normal cycle | 9.8 critical | 3% | 2016-04-06 |
| CVE-2019-6440 | Zemana AntiMalware before 3.0.658 Beta mishandles update logic. | In your normal cycle | 9.8 critical | 3% | 2019-01-16 |
| CVE-2020-12504 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8… | In your normal cycle | 9.8 critical | 3% | 2020-10-15 |
| CVE-2020-22276 | WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry. | In your normal cycle | 9.8 critical | 3% | 2020-11-04 |
| CVE-2026-59726 | Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp… | In your normal cycle | 10.0 critical | 3% | 2026-07-09 |
| CVE-2017-6895 | USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml. | In your normal cycle | 9.8 critical | 3% | 2017-03-23 |
| CVE-2019-17625 | There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs… | In your normal cycle | 9.0 critical | 3% | 2019-10-16 |
| CVE-2022-33872 | An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of F… | In your normal cycle | 9.8 critical | 3% | 2022-10-18 |
| CVE-2022-33874 | An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of Fort… | In your normal cycle | 9.8 critical | 3% | 2022-10-18 |
| CVE-2020-28022 | Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer. This occurs when processing name=value pairs w… | In your normal cycle | 9.8 critical | 3% | 2021-05-06 |
| CVE-2017-6925 | In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, up… | In your normal cycle | 9.8 critical | 3% | 2019-01-15 |
| CVE-2021-32563 | An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to… | In your normal cycle | 9.8 critical | 3% | 2021-05-11 |
| CVE-2021-1965 | Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti… | In your normal cycle | 9.8 critical | 3% | 2021-07-13 |
| CVE-2019-13172 | Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web… | In your normal cycle | 9.8 critical | 3% | 2020-03-13 |
| CVE-2020-29576 | The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by af… | In your normal cycle | 9.8 critical | 3% | 2020-12-08 |
| CVE-2020-7621 | strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' functi… | In your normal cycle | 9.8 critical | 3% | 2020-04-02 |
| CVE-2014-4984 | Déjà Vu Crescendo Sales CRM has remote SQL Injection | In your normal cycle | 9.8 critical | 3% | 2020-01-10 |
| CVE-2023-27032 | Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups(… | In your normal cycle | 9.8 critical | 3% | 2023-04-12 |
| CVE-2022-36231 | pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3. | In your normal cycle | 9.8 critical | 3% | 2023-02-23 |
| CVE-2019-20786 | handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject arb… | In your normal cycle | 9.8 critical | 3% | 2020-04-19 |
| CVE-2026-8181 | The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass… | In your normal cycle | 9.8 critical | 3% | 2026-05-14 |
| CVE-2014-8174 | eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files. | In your normal cycle | 9.8 critical | 3% | 2017-09-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt