CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,370 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
37,054 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-0839 | Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0. | In your normal cycle | 9.8 critical | 3% | 2022-03-04 |
| CVE-2017-18345 | The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an… | In your normal cycle | 9.8 critical | 3% | 2018-08-26 |
| CVE-2021-34770 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 900… | In your normal cycle | 10.0 critical | 3% | 2021-09-23 |
| CVE-2015-8871 | Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact vi… | In your normal cycle | 9.8 critical | 3% | 2016-09-21 |
| CVE-2017-9980 | In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing command… | In your normal cycle | 9.8 critical | 3% | 2017-07-21 |
| CVE-2019-1003034 | A sandbox bypass vulnerability exists in Jenkins Job DSL Plugin 1.71 and earlier in job-dsl-core/src/main/groovy/javaposse/jobdsl/dsl/AbstractDslScrip… | In your normal cycle | 9.9 critical | 3% | 2019-03-08 |
| CVE-2018-18728 | An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execu… | In your normal cycle | 9.8 critical | 3% | 2018-10-29 |
| CVE-2021-21820 | A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network reques… | In your normal cycle | 9.8 critical | 3% | 2021-07-16 |
| CVE-2017-10346 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE:… | In your normal cycle | 9.6 critical | 3% | 2017-10-19 |
| CVE-2020-13854 | Artica Pandora FMS 7.44 allows privilege escalation. | In your normal cycle | 9.8 critical | 3% | 2020-06-11 |
| CVE-2021-25944 | Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote… | In your normal cycle | 9.8 critical | 3% | 2021-05-25 |
| CVE-2021-25945 | Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code… | In your normal cycle | 9.8 critical | 3% | 2021-05-26 |
| CVE-2021-25947 | Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code… | In your normal cycle | 9.8 critical | 3% | 2021-06-03 |
| CVE-2021-25953 | Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead to remote cod… | In your normal cycle | 9.8 critical | 3% | 2021-07-14 |
| CVE-2021-21433 | Discord Recon Server is a bot that allows you to do your reconnaissance process from your Discord. Remote code execution in version 0.0.1 would allow… | In your normal cycle | 9.9 critical | 3% | 2021-04-09 |
| CVE-2016-10308 | Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across a… | In your normal cycle | 9.8 critical | 3% | 2017-03-30 |
| CVE-2019-9884 | eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management p… | In your normal cycle | 9.8 critical | 3% | 2019-07-25 |
| CVE-2017-14080 | Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific part… | In your normal cycle | 9.8 critical | 3% | 2017-09-22 |
| CVE-2018-9355 | In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote code exe… | In your normal cycle | 9.8 critical | 3% | 2018-11-06 |
| CVE-2020-14119 | There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi rou… | In your normal cycle | 9.8 critical | 3% | 2021-09-16 |
| CVE-2017-1002023 | Vulnerability in wordpress plugin Easy Team Manager v1.3.2, The code does not sanitize id before making it part of an SQL statement in file ./easy-tea… | In your normal cycle | 9.8 critical | 3% | 2017-09-14 |
| CVE-2018-5096 | A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerabi… | In your normal cycle | 9.8 critical | 3% | 2018-06-11 |
| CVE-2020-9529 | Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices,… | In your normal cycle | 9.8 critical | 3% | 2020-08-10 |
| CVE-2021-33907 | The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files w… | In your normal cycle | 9.8 critical | 3% | 2021-09-27 |
| CVE-2019-6288 | Edgecore ECS2020 Firmware 1.0.0.0 devices allow Unauthenticated Command Injection via the command1 HTTP header to the /EXCU_SHELL URI. | In your normal cycle | 9.8 critical | 3% | 2021-09-22 |
| CVE-2017-17067 | Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the… | In your normal cycle | 9.8 critical | 3% | 2017-11-30 |
| CVE-2022-24165 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vulne… | In your normal cycle | 9.8 critical | 3% | 2022-02-04 |
| CVE-2022-24167 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerabili… | In your normal cycle | 9.8 critical | 3% | 2022-02-04 |
| CVE-2022-24168 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulnera… | In your normal cycle | 9.8 critical | 3% | 2022-02-04 |
| CVE-2022-24170 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpSecTunnel. This vul… | In your normal cycle | 9.8 critical | 3% | 2022-02-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt