CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,123 CVEs
1,733 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-31819 | An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.p… | Patch early | 9.8 critical | 15.6% | 2024-04-10 |
| CVE-2021-3437 | Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denial of ser… | Patch early | 9.8 critical | 15.6% | 2022-12-12 |
| CVE-2023-22501 | An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user… | Patch early | 9.1 critical | 15.5% | 2023-02-01 |
| CVE-2023-38944 | An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access control an… | Patch early | 9.8 critical | 15.5% | 2024-03-06 |
| CVE-2025-4322 | The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to… | Patch early | 9.8 critical | 15.5% | 2025-05-20 |
| CVE-2024-42812 | In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who… | Patch early | 9.8 critical | 15.5% | 2024-08-19 |
| CVE-2020-4210 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP c… | Patch early | 9.8 critical | 15.5% | 2020-02-24 |
| CVE-2020-4213 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP c… | Patch early | 9.8 critical | 15.5% | 2020-02-24 |
| CVE-2020-4222 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP c… | Patch early | 9.8 critical | 15.5% | 2020-02-24 |
| CVE-2016-5771 | spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage col… | Patch early | 9.8 critical | 15.5% | 2016-08-07 |
| CVE-2019-10655 | Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unaut… | Patch early | 9.8 critical | 15.5% | 2019-03-30 |
| CVE-2018-18556 | A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execute the pppd binary with elevat… | Patch early | 9.9 critical | 15.4% | 2018-12-17 |
| CVE-2025-43564 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file… | Patch early | 9.1 critical | 15.4% | 2025-05-13 |
| CVE-2018-4947 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerab… | Patch early | 9.8 critical | 15.4% | 2018-07-09 |
| CVE-2018-4948 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerab… | Patch early | 9.8 critical | 15.4% | 2018-07-09 |
| CVE-2018-4966 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerab… | Patch early | 9.8 critical | 15.4% | 2018-07-09 |
| CVE-2018-4968 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerab… | Patch early | 9.8 critical | 15.4% | 2018-07-09 |
| CVE-2018-4978 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerab… | Patch early | 9.8 critical | 15.4% | 2018-07-09 |
| CVE-2018-4984 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerab… | Patch early | 9.8 critical | 15.4% | 2018-07-09 |
| CVE-2019-0586 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microso… | Patch early | 9.8 critical | 15.4% | 2019-01-08 |
| CVE-2024-1305 | tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overfl… | Patch early | 9.8 critical | 15.4% | 2024-07-08 |
| CVE-2024-10542 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an autho… | Patch early | 9.8 critical | 15.4% | 2024-11-26 |
| CVE-2024-42905 | Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device a… | Patch early | 9.8 critical | 15.4% | 2024-08-28 |
| CVE-2016-8511 | A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v10… | Patch early | 9.8 critical | 15.3% | 2018-02-15 |
| CVE-2018-17936 | NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the serve… | Patch early | 9.8 critical | 15.3% | 2018-11-27 |
| CVE-2025-43563 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file… | Patch early | 9.1 critical | 15.3% | 2025-05-13 |
| CVE-2023-41998 | Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows a… | Patch early | 9.8 critical | 15.3% | 2023-11-27 |
| CVE-2017-17106 | Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/pa… | Patch early | 9.8 critical | 15.3% | 2017-12-19 |
| CVE-2019-17361 | In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticate… | Patch early | 9.8 critical | 15.2% | 2020-01-17 |
| CVE-2015-2560 | Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModify… | Patch early | 9.8 critical | 15.2% | 2017-08-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt