CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,295 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,710 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-20158 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to f… | Patch early | 9.8 critical | 10.9% | 2021-12-30 |
| CVE-2017-6416 | An issue was discovered in SysGauge 1.5.18. A buffer overflow vulnerability in SMTP connection verification leads to arbitrary code execution. The att… | Patch early | 9.8 critical | 10.9% | 2017-03-06 |
| CVE-2018-12815 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnera… | Patch early | 9.8 critical | 10.8% | 2018-07-20 |
| CVE-2022-0760 | The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the… | Patch early | 9.8 critical | 10.8% | 2022-03-21 |
| CVE-2018-11780 | A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2. | Patch early | 9.8 critical | 10.8% | 2018-09-17 |
| CVE-2018-1260 | Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contain… | Patch early | 9.8 critical | 10.8% | 2018-05-11 |
| CVE-2017-7895 | The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attack… | Patch early | 9.8 critical | 10.8% | 2017-04-28 |
| CVE-2005-1513 | Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote at… | Patch early | 9.8 critical | 10.8% | 2005-05-11 |
| CVE-2021-20136 | ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticat… | Patch early | 9.8 critical | 10.8% | 2021-11-01 |
| CVE-2019-14540 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig. | Patch early | 9.8 critical | 10.8% | 2019-09-15 |
| CVE-2024-44466 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and… | Patch early | 9.8 critical | 10.7% | 2024-09-11 |
| CVE-2015-4599 | The SoapFault::__toString method in ext/soap/soap.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtai… | Patch early | 9.8 critical | 10.7% | 2016-05-16 |
| CVE-2015-4600 | The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (… | Patch early | 9.8 critical | 10.7% | 2016-05-16 |
| CVE-2017-6640 | A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administra… | Patch early | 9.8 critical | 10.7% | 2017-06-08 |
| CVE-2018-16395 | An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When two… | Patch early | 9.8 critical | 10.7% | 2018-11-16 |
| CVE-2025-45858 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function. | Patch early | 9.8 critical | 10.7% | 2025-05-13 |
| CVE-2024-6037 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including… | Patch early | 9.1 critical | 10.7% | 2024-07-10 |
| CVE-2016-10166 | Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attack… | Patch early | 9.8 critical | 10.7% | 2017-03-15 |
| CVE-2024-45409 | The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify… | Patch early | 10.0 critical | 10.7% | 2024-09-10 |
| CVE-2018-4950 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds write v… | Patch early | 9.8 critical | 10.7% | 2018-07-09 |
| CVE-2015-4602 | The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote… | Patch early | 9.8 critical | 10.7% | 2016-05-16 |
| CVE-2018-6913 | Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item co… | Patch early | 9.8 critical | 10.7% | 2018-04-17 |
| CVE-2019-10993 | In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute arbitrary c… | Patch early | 9.8 critical | 10.7% | 2019-06-28 |
| CVE-2022-1692 | The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL… | Patch early | 9.8 critical | 10.6% | 2022-06-08 |
| CVE-2022-37070 | H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList. | Patch early | 9.8 critical | 10.6% | 2022-08-25 |
| CVE-2021-31535 | LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request… | Patch early | 9.8 critical | 10.6% | 2021-05-27 |
| CVE-2016-6330 | The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote at… | Patch early | 9.8 critical | 10.6% | 2016-09-27 |
| CVE-2020-17051 | Windows Network File System Remote Code Execution Vulnerability | Patch early | 9.8 critical | 10.6% | 2020-11-11 |
| CVE-2022-36944 | Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction w… | Patch early | 9.8 critical | 10.6% | 2022-09-23 |
| CVE-2021-21998 | VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network acce… | Patch early | 9.8 critical | 10.6% | 2021-06-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt