CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,370 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,054 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-13651 | TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5). | In your normal cycle | 9.8 critical | 3% | 2019-10-24 |
| CVE-2017-15670 | The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow in the glob function in glob.c… | In your normal cycle | 9.8 critical | 3% | 2017-10-20 |
| CVE-2017-6199 | A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field. | In your normal cycle | 9.8 critical | 3% | 2018-02-06 |
| CVE-2026-3296 | The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrus… | In your normal cycle | 9.8 critical | 3% | 2026-04-08 |
| CVE-2007-6762 | In the Linux kernel before 2.6.20, there is an off-by-one bug in net/netlabel/netlabel_cipso_v4.c where it is possible to overflow the doi_def->tags[]… | In your normal cycle | 9.8 critical | 3% | 2019-07-27 |
| CVE-2015-6314 | Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change confi… | In your normal cycle | 9.8 critical | 3% | 2016-01-15 |
| CVE-2015-8360 | An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialize… | In your normal cycle | 9.8 critical | 3% | 2016-02-08 |
| CVE-2014-3539 | base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveraging an unsafe call to pickle.lo… | In your normal cycle | 9.8 critical | 3% | 2018-04-06 |
| CVE-2018-5148 | A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counte… | In your normal cycle | 9.8 critical | 3% | 2018-06-11 |
| CVE-2021-1834 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina… | In your normal cycle | 9.8 critical | 3% | 2021-09-08 |
| CVE-2021-42575 | The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements. | In your normal cycle | 9.8 critical | 3% | 2021-10-18 |
| CVE-2021-27446 | The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privile… | In your normal cycle | 10.0 critical | 3% | 2022-05-16 |
| CVE-2020-35863 | An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situa… | In your normal cycle | 9.8 critical | 3% | 2020-12-31 |
| CVE-2018-15555 | On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and password "admin" by using the en… | In your normal cycle | 9.8 critical | 3% | 2019-06-28 |
| CVE-2022-28738 | A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted… | In your normal cycle | 9.8 critical | 3% | 2022-05-09 |
| CVE-2022-38250 | Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page. | In your normal cycle | 9.8 critical | 3% | 2022-09-07 |
| CVE-2013-2612 | Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with root privi… | In your normal cycle | 9.8 critical | 3% | 2020-01-27 |
| CVE-2021-23377 | This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker… | In your normal cycle | 9.8 critical | 3% | 2021-04-18 |
| CVE-2021-44088 | An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via… | In your normal cycle | 9.8 critical | 3% | 2022-03-17 |
| CVE-2022-25411 | A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file. | In your normal cycle | 9.8 critical | 3% | 2022-02-28 |
| CVE-2017-10102 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u15… | In your normal cycle | 9.0 critical | 3% | 2017-08-08 |
| CVE-2015-8747 | The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name. | In your normal cycle | 10.0 critical | 3% | 2016-02-03 |
| CVE-2015-1000000 | Remote file upload vulnerability in mailcwp v1.99 wordpress plugin | In your normal cycle | 9.8 critical | 3% | 2016-10-06 |
| CVE-2017-5430 | Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we pre… | In your normal cycle | 9.8 critical | 3% | 2018-06-11 |
| CVE-2020-5656 | Improper access control vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Modul… | In your normal cycle | 9.8 critical | 3% | 2020-11-02 |
| CVE-2012-6712 | In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption. | In your normal cycle | 9.8 critical | 3% | 2019-07-27 |
| CVE-2019-11027 | Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID P… | In your normal cycle | 9.8 critical | 3% | 2019-06-10 |
| CVE-2019-9774 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at bits.c. | In your normal cycle | 9.1 critical | 3% | 2019-03-14 |
| CVE-2019-9775 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_CONTROL at dwg.spec. | In your normal cycle | 9.1 critical | 3% | 2019-03-14 |
| CVE-2018-7785 | In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass. | In your normal cycle | 9.8 critical | 3% | 2018-07-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt