CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,069 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-8302 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microso… | Patch early | 9.8 critical | 25.5% | 2018-08-15 |
| CVE-2020-26525 | Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remot… | Patch early | 9.1 critical | 25.5% | 2020-10-02 |
| CVE-2016-5636 | Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote… | Patch early | 9.8 critical | 25.5% | 2016-09-02 |
| CVE-2016-3227 | Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary cod… | Patch early | 9.8 critical | 25.5% | 2016-06-16 |
| CVE-2022-21186 | The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of… | Patch early | 9.8 critical | 25.4% | 2022-08-05 |
| CVE-2016-3955 | The usbip_recv_xbuff function in drivers/usb/usbip/usbip_common.c in the Linux kernel before 4.5.3 allows remote attackers to cause a denial of servic… | Patch early | 9.8 critical | 25.3% | 2016-07-03 |
| CVE-2021-20045 | A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute… | Patch early | 9.8 critical | 25.2% | 2021-12-08 |
| CVE-2021-27691 | Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware v… | Patch early | 9.8 critical | 25.2% | 2021-04-16 |
| CVE-2018-5064 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write v… | Patch early | 9.8 critical | 25.1% | 2018-07-20 |
| CVE-2018-5069 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write v… | Patch early | 9.8 critical | 25.1% | 2018-07-20 |
| CVE-2018-5070 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write v… | Patch early | 9.8 critical | 25.1% | 2018-07-20 |
| CVE-2016-2298 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vector… | Patch early | 9.8 critical | 25.1% | 2016-05-14 |
| CVE-2022-38621 | Doufox v0.0.4 was discovered to contain a remote code execution (RCE) vulnerability via the edit file page. This vulnerability allows attackers to exe… | Patch early | 9.8 critical | 25% | 2022-09-16 |
| CVE-2018-12754 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write v… | Patch early | 9.8 critical | 25% | 2018-07-20 |
| CVE-2018-12755 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write v… | Patch early | 9.8 critical | 25% | 2018-07-20 |
| CVE-2012-6710 | ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login re… | Patch early | 9.8 critical | 25% | 2018-10-07 |
| CVE-2022-41772 | Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This pa… | Patch early | 9.8 critical | 24.9% | 2022-10-31 |
| CVE-2025-47646 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registr… | Patch early | 9.8 critical | 24.9% | 2025-05-23 |
| CVE-2023-31983 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function i… | Patch early | 9.8 critical | 24.9% | 2023-05-12 |
| CVE-2018-10143 | The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level comm… | Patch early | 9.8 critical | 24.8% | 2018-12-12 |
| CVE-2022-25084 | TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attacke… | Patch early | 9.8 critical | 24.8% | 2022-02-24 |
| CVE-2023-34990 | A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or com… | Patch early | 9.8 critical | 24.8% | 2024-12-18 |
| CVE-2023-46456 | In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionalit… | Patch early | 9.8 critical | 24.7% | 2023-12-12 |
| CVE-2025-34392 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled… | Patch early | 9.8 critical | 24.7% | 2025-12-10 |
| CVE-2022-34531 | DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php. | Patch early | 9.8 critical | 24.7% | 2022-07-29 |
| CVE-2022-1952 | The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to… | Patch early | 9.8 critical | 24.6% | 2022-07-11 |
| CVE-2024-4701 | A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18 | Patch early | 9.9 critical | 24.6% | 2024-05-14 |
| CVE-2025-5120 | A sandbox escape vulnerability was identified in huggingface/smolagents version 1.14.0, allowing attackers to bypass the restricted execution environm… | Patch early | 10.0 critical | 24.6% | 2025-07-27 |
| CVE-2021-27114 | An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment route, a very long text entry… | Patch early | 9.8 critical | 24.6% | 2021-04-14 |
| CVE-2024-29671 | Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler com… | Patch early | 9.8 critical | 24.5% | 2024-12-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt