CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,212 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,709 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-20216 | FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerFl… | Patch early | 9.8 critical | 12% | 2026-01-08 |
| CVE-2021-25140 | A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an app… | Patch early | 9.8 critical | 12% | 2021-02-09 |
| CVE-2021-24915 | The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original… | Patch early | 9.8 critical | 12% | 2021-11-29 |
| CVE-2022-29660 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del. | Patch early | 9.8 critical | 12% | 2022-05-26 |
| CVE-2016-5681 | Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.… | Patch early | 9.8 critical | 11.9% | 2016-08-25 |
| CVE-2022-24954 | Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' an… | Patch early | 9.8 critical | 11.9% | 2022-02-11 |
| CVE-2021-24078 | Windows DNS Server Remote Code Execution Vulnerability | Patch early | 9.8 critical | 11.9% | 2021-02-25 |
| CVE-2022-22805 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an… | Patch early | 9.8 critical | 11.9% | 2022-03-09 |
| CVE-2016-4543 | The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes,… | Patch early | 9.8 critical | 11.9% | 2016-05-22 |
| CVE-2019-9948 | urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that b… | Patch early | 9.1 critical | 11.8% | 2019-03-23 |
| CVE-2019-15679 | TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This atta… | Patch early | 9.8 critical | 11.8% | 2019-10-29 |
| CVE-2016-0788 | The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener. | Patch early | 9.8 critical | 11.8% | 2016-04-07 |
| CVE-2021-27965 | The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x8… | Patch early | 9.8 critical | 11.8% | 2021-03-05 |
| CVE-2018-4918 | Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier have an exploitable out-of-bounds… | Patch early | 9.8 critical | 11.8% | 2018-05-19 |
| CVE-2018-15126 | LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension tha… | Patch early | 9.8 critical | 11.8% | 2018-12-19 |
| CVE-2023-0755 | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute… | Patch early | 9.8 critical | 11.8% | 2023-02-23 |
| CVE-2015-7853 | The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code or… | Patch early | 9.8 critical | 11.8% | 2017-08-07 |
| CVE-2024-47066 | Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `s… | Patch early | 9.0 critical | 11.8% | 2024-09-23 |
| CVE-2014-8731 | PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of th… | Patch early | 9.8 critical | 11.8% | 2017-03-23 |
| CVE-2021-25830 | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion… | Patch early | 9.8 critical | 11.8% | 2021-03-01 |
| CVE-2024-6028 | The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including,… | Patch early | 9.8 critical | 11.8% | 2024-06-25 |
| CVE-2018-14649 | It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by setti… | Patch early | 9.8 critical | 11.7% | 2018-10-09 |
| CVE-2016-7167 | Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.5… | Patch early | 9.8 critical | 11.7% | 2016-10-07 |
| CVE-2017-13708 | Buffer overflow in the web server service in VX Search Enterprise 10.0.14 allows remote attackers to execute arbitrary code via a crafted GET request. | Patch early | 9.8 critical | 11.7% | 2017-08-31 |
| CVE-2024-39360 | An os command injection vulnerability exists in the nas.cgi remove_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP… | Patch early | 9.1 critical | 11.7% | 2025-01-14 |
| CVE-2018-15981 | Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. | Patch early | 9.8 critical | 11.7% | 2018-11-29 |
| CVE-2018-18311 | Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | Patch early | 9.8 critical | 11.7% | 2018-12-07 |
| CVE-2016-3132 | Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to ex… | Patch early | 9.8 critical | 11.7% | 2016-08-07 |
| CVE-2024-46628 | Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the… | Patch early | 9.8 critical | 11.7% | 2024-09-26 |
| CVE-2017-3082 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the LocaleID class. Successful exploitation… | Patch early | 9.8 critical | 11.7% | 2017-06-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt