CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,267 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,711 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-26897 | Windows DNS Server Remote Code Execution Vulnerability | Patch early | 9.8 critical | 11.6% | 2021-03-11 |
| CVE-2023-26068 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4). | Patch early | 9.8 critical | 11.6% | 2023-04-10 |
| CVE-2018-4958 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… | Patch early | 9.8 critical | 11.6% | 2018-07-09 |
| CVE-2018-4959 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… | Patch early | 9.8 critical | 11.6% | 2018-07-09 |
| CVE-2018-4961 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… | Patch early | 9.8 critical | 11.6% | 2018-07-09 |
| CVE-2018-4977 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… | Patch early | 9.8 critical | 11.6% | 2018-07-09 |
| CVE-2018-4983 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… | Patch early | 9.8 critical | 11.6% | 2018-07-09 |
| CVE-2018-4988 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… | Patch early | 9.8 critical | 11.6% | 2018-07-09 |
| CVE-2018-4989 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… | Patch early | 9.8 critical | 11.6% | 2018-07-09 |
| CVE-2022-3184 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to ac… | Patch early | 9.8 critical | 11.6% | 2022-12-21 |
| CVE-2024-52765 | H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter. | Patch early | 9.8 critical | 11.6% | 2024-11-20 |
| CVE-2018-1000120 | A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or w… | Patch early | 9.8 critical | 11.6% | 2018-03-14 |
| CVE-2022-0817 | The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to… | Patch early | 9.8 critical | 11.6% | 2022-05-09 |
| CVE-2017-12377 | ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of… | Patch early | 9.8 critical | 11.6% | 2018-01-26 |
| CVE-2025-45488 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter… | Patch early | 9.8 critical | 11.6% | 2025-05-06 |
| CVE-2021-38408 | A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user… | Patch early | 9.8 critical | 11.6% | 2021-09-09 |
| CVE-2022-25450 | Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function. | Patch early | 9.8 critical | 11.6% | 2022-03-18 |
| CVE-2020-15639 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is… | Patch early | 9.8 critical | 11.5% | 2020-08-25 |
| CVE-2018-20338 | Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section. | Patch early | 9.8 critical | 11.5% | 2018-12-21 |
| CVE-2018-4872 | An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier v… | Patch early | 10.0 critical | 11.5% | 2018-02-27 |
| CVE-2020-12001 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:… | Patch early | 9.8 critical | 11.5% | 2020-06-15 |
| CVE-2021-25831 | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of th… | Patch early | 9.8 critical | 11.5% | 2021-03-01 |
| CVE-2019-9653 | NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to ha… | Patch early | 9.8 critical | 11.5% | 2019-05-31 |
| CVE-2025-28146 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/… | Patch early | 9.8 critical | 11.5% | 2025-04-04 |
| CVE-2016-1051 | Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Ac… | Patch early | 9.8 critical | 11.5% | 2016-05-11 |
| CVE-2025-45487 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function. | Patch early | 9.8 critical | 11.5% | 2025-05-06 |
| CVE-2019-0719 | A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticat… | Patch early | 9.1 critical | 11.4% | 2019-11-12 |
| CVE-2024-7261 | The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earl… | Patch early | 9.8 critical | 11.4% | 2024-09-03 |
| CVE-2019-14813 | A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, ena… | Patch early | 9.8 critical | 11.4% | 2019-09-06 |
| CVE-2022-25347 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrar… | Patch early | 9.8 critical | 11.4% | 2022-03-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt