CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,295 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,710 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-8749 | Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks. | Patch early | 9.8 critical | 10.6% | 2017-03-28 |
| CVE-2018-19360 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms cl… | Patch early | 9.8 critical | 10.6% | 2019-01-02 |
| CVE-2018-19361 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from pol… | Patch early | 9.8 critical | 10.6% | 2019-01-02 |
| CVE-2018-19362 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core clas… | Patch early | 9.8 critical | 10.6% | 2019-01-02 |
| CVE-2025-61808 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could l… | Patch early | 9.1 critical | 10.6% | 2025-12-10 |
| CVE-2016-1988 | HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information… | Patch early | 9.8 critical | 10.6% | 2016-03-15 |
| CVE-2016-1989 | HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information… | Patch early | 9.8 critical | 10.6% | 2016-03-15 |
| CVE-2025-54123 | Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command inject… | Patch early | 9.8 critical | 10.5% | 2025-09-10 |
| CVE-2019-19012 | An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset… | Patch early | 9.8 critical | 10.5% | 2019-11-17 |
| CVE-2024-46048 | Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i | Patch early | 9.8 critical | 10.5% | 2024-09-13 |
| CVE-2020-24648 | A accessmgrservlet classname deserialization of untrusted data remote code execution vulnerability was discovered in HPE Intelligent Management Center… | Patch early | 9.8 critical | 10.5% | 2020-10-19 |
| CVE-2017-16082 | A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. Ther… | Patch early | 9.8 critical | 10.5% | 2018-06-07 |
| CVE-2021-25283 | An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks. | Patch early | 9.8 critical | 10.5% | 2021-02-27 |
| CVE-2016-9343 | An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions p… | Patch early | 10.0 critical | 10.5% | 2017-02-13 |
| CVE-2016-5743 | Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed in SIMATIC PCS 7 through 8.1… | Patch early | 9.8 critical | 10.5% | 2016-07-22 |
| CVE-2021-37925 | Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability. | Patch early | 9.8 critical | 10.5% | 2021-09-22 |
| CVE-2016-2008 | HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors. | Patch early | 9.8 critical | 10.5% | 2016-04-21 |
| CVE-2017-10992 | In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/… | Patch early | 9.8 critical | 10.5% | 2020-03-10 |
| CVE-2022-24856 | FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF… | Patch early | 9.1 critical | 10.5% | 2022-05-17 |
| CVE-2021-3401 | Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformpluginpath arg… | Patch early | 9.8 critical | 10.5% | 2021-02-04 |
| CVE-2026-25137 | The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the d… | Patch early | 9.1 critical | 10.5% | 2026-02-02 |
| CVE-2022-20779 | Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM)… | Patch early | 9.9 critical | 10.5% | 2022-05-04 |
| CVE-2025-53120 | A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s configu… | Patch early | 9.4 critical | 10.5% | 2025-08-25 |
| CVE-2018-14721 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure t… | Patch early | 10.0 critical | 10.5% | 2019-01-02 |
| CVE-2019-14450 | A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user co… | Patch early | 9.8 critical | 10.4% | 2019-10-28 |
| CVE-2024-9234 | The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads du… | Patch early | 9.8 critical | 10.4% | 2024-10-11 |
| CVE-2022-25414 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR. | Patch early | 9.8 critical | 10.4% | 2022-02-24 |
| CVE-2022-32032 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the deviceList parameter in the function formAddMacfilterRule. | Patch early | 9.8 critical | 10.4% | 2022-07-01 |
| CVE-2018-25115 | Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulne… | Patch early | 9.8 critical | 10.4% | 2025-08-27 |
| CVE-2021-35324 | A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication. | Patch early | 9.8 critical | 10.4% | 2021-08-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt