CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,367 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,054 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-21891 | A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A… | In your normal cycle | 9.1 critical | 3% | 2021-12-22 |
| CVE-2021-23390 | The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. | In your normal cycle | 9.8 critical | 3% | 2021-07-12 |
| CVE-2020-14244 | A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker re… | In your normal cycle | 9.8 critical | 3% | 2020-12-14 |
| CVE-2019-15519 | Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin. | In your normal cycle | 9.8 critical | 3% | 2019-08-23 |
| CVE-2015-9316 | The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id… | In your normal cycle | 9.8 critical | 3% | 2019-08-14 |
| CVE-2026-81467 | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'… | In your normal cycle | 9.8 critical | 3% | 2026-09-10 |
| CVE-2020-28172 | A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in co… | In your normal cycle | 9.8 critical | 3% | 2021-03-31 |
| CVE-2016-1925 | Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1… | In your normal cycle | 9.8 critical | 3% | 2017-01-23 |
| CVE-2017-1000081 | Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution. | In your normal cycle | 9.8 critical | 3% | 2017-07-17 |
| CVE-2016-7405 | The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks… | In your normal cycle | 9.8 critical | 3% | 2016-10-03 |
| CVE-2022-20229 | In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead… | In your normal cycle | 9.8 critical | 3% | 2022-07-13 |
| CVE-2021-42114 | Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attacks… | In your normal cycle | 9.0 critical | 3% | 2021-11-16 |
| CVE-2022-37968 | Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allo… | In your normal cycle | 10.0 critical | 3% | 2022-10-11 |
| CVE-2026-18072 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Ha… | In your normal cycle | 9.8 critical | 3% | 2026-07-29 |
| CVE-2011-1180 | Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux kernel before 2.6.39 allow rem… | In your normal cycle | 9.8 critical | 3% | 2013-06-08 |
| CVE-2019-17042 | An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser… | In your normal cycle | 9.8 critical | 3% | 2019-10-07 |
| CVE-2017-5668 | bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrar… | In your normal cycle | 9.8 critical | 3% | 2017-03-14 |
| CVE-2021-42343 | An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters started with dask.distributed.LocalC… | In your normal cycle | 9.8 critical | 3% | 2021-10-26 |
| CVE-2026-6942 | radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by byp… | In your normal cycle | 9.8 critical | 3% | 2026-04-23 |
| CVE-2021-43905 | Microsoft Office app Remote Code Execution Vulnerability | In your normal cycle | 9.6 critical | 3% | 2021-12-15 |
| CVE-2017-14008 | GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successfu… | In your normal cycle | 9.8 critical | 3% | 2018-03-20 |
| CVE-2021-33806 | The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObje… | In your normal cycle | 9.8 critical | 3% | 2021-06-03 |
| CVE-2017-6869 | A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user t… | In your normal cycle | 9.8 critical | 3% | 2017-08-08 |
| CVE-2017-9944 | A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of… | In your normal cycle | 9.8 critical | 3% | 2017-12-27 |
| CVE-2018-5187 | Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough e… | In your normal cycle | 9.8 critical | 3% | 2018-10-18 |
| CVE-2017-12368 | A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording For… | In your normal cycle | 9.6 critical | 3% | 2017-11-30 |
| CVE-2017-12369 | A "Cisco WebEx Network Recording Player Out-of-Bounds Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF… | In your normal cycle | 9.6 critical | 3% | 2017-11-30 |
| CVE-2017-12370 | A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording For… | In your normal cycle | 9.6 critical | 3% | 2017-11-30 |
| CVE-2017-12371 | A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording For… | In your normal cycle | 9.6 critical | 3% | 2017-11-30 |
| CVE-2017-12372 | A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording For… | In your normal cycle | 9.6 critical | 3% | 2017-11-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt