CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,247 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,051 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-39296 | In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system. | In your normal cycle | 10.0 critical | 3% | 2021-09-09 |
| CVE-2021-45003 | Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php throug… | In your normal cycle | 9.8 critical | 3% | 2022-01-10 |
| CVE-2019-7253 | Linear eMerge E3-Series devices allow Directory Traversal. | In your normal cycle | 9.8 critical | 3% | 2019-07-02 |
| CVE-2022-42920 | Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writ… | In your normal cycle | 9.8 critical | 3% | 2022-11-07 |
| CVE-2020-19113 | Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution. | In your normal cycle | 9.8 critical | 3% | 2021-05-06 |
| CVE-2018-0349 | A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating sy… | In your normal cycle | 9.8 critical | 3% | 2018-07-18 |
| CVE-2018-18933 | The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of se… | In your normal cycle | 9.1 critical | 3% | 2018-11-05 |
| CVE-2020-9918 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A remot… | In your normal cycle | 9.8 critical | 3% | 2020-10-16 |
| CVE-2020-26098 | cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485). | In your normal cycle | 9.8 critical | 3% | 2020-09-25 |
| CVE-2020-28194 | Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an i… | In your normal cycle | 9.8 critical | 3% | 2021-02-01 |
| CVE-2020-7465 | The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to… | In your normal cycle | 9.8 critical | 3% | 2020-10-06 |
| CVE-2019-9125 | An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does… | In your normal cycle | 9.8 critical | 3% | 2019-02-25 |
| CVE-2022-28575 | It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, w… | In your normal cycle | 9.8 critical | 3% | 2022-05-05 |
| CVE-2022-28577 | It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, whic… | In your normal cycle | 9.8 critical | 3% | 2022-05-05 |
| CVE-2022-28578 | It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which a… | In your normal cycle | 9.8 critical | 3% | 2022-05-05 |
| CVE-2022-28579 | It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, whic… | In your normal cycle | 9.8 critical | 3% | 2022-05-05 |
| CVE-2022-28580 | It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, whic… | In your normal cycle | 9.8 critical | 3% | 2022-05-05 |
| CVE-2022-28581 | It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, wh… | In your normal cycle | 9.8 critical | 3% | 2022-05-05 |
| CVE-2022-28582 | It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, whic… | In your normal cycle | 9.8 critical | 3% | 2022-05-05 |
| CVE-2022-28583 | It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which a… | In your normal cycle | 9.8 critical | 3% | 2022-05-05 |
| CVE-2022-28584 | It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which… | In your normal cycle | 9.8 critical | 3% | 2022-05-05 |
| CVE-2019-3772 | Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were su… | In your normal cycle | 9.8 critical | 3% | 2019-01-18 |
| CVE-2012-3503 | The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default ins… | In your normal cycle | 9.8 critical | 3% | 2012-08-25 |
| CVE-2022-28805 | singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer ov… | In your normal cycle | 9.1 critical | 3% | 2022-04-08 |
| CVE-2022-26520 | In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files thro… | In your normal cycle | 9.8 critical | 3% | 2022-03-10 |
| CVE-2019-17526 | An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web appl… | In your normal cycle | 9.8 critical | 3% | 2019-10-18 |
| CVE-2019-8746 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iClo… | In your normal cycle | 9.8 critical | 3% | 2020-10-27 |
| CVE-2021-27335 | KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections… | In your normal cycle | 9.8 critical | 3% | 2021-02-18 |
| CVE-2016-4375 | Multiple unspecified vulnerabilities in HPE Integrated Lights-Out 3 (aka iLO 3) firmware before 1.88, Integrated Lights-Out 4 (aka iLO 4) firmware bef… | In your normal cycle | 9.8 critical | 3% | 2016-09-08 |
| CVE-2020-11811 | In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type val… | In your normal cycle | 9.8 critical | 3% | 2020-04-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt