CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,295 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,710 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-25579 | TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr. | Patch early | 9.8 critical | 10.4% | 2025-03-28 |
| CVE-2013-5618 | Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox b… | Patch early | 9.8 critical | 10.4% | 2013-12-11 |
| CVE-2018-20555 | The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, cons… | Patch early | 9.8 critical | 10.4% | 2019-03-21 |
| CVE-2025-1302 | Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can… | Patch early | 9.8 critical | 10.4% | 2025-02-15 |
| CVE-2022-37056 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main, | Patch early | 9.8 critical | 10.4% | 2022-08-28 |
| CVE-2026-20147 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating… | Patch early | 9.9 critical | 10.4% | 2026-04-15 |
| CVE-2021-38389 | Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code. | Patch early | 9.8 critical | 10.4% | 2021-10-18 |
| CVE-2024-4443 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listing… | Patch early | 9.8 critical | 10.4% | 2024-05-22 |
| CVE-2023-20078 | Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute a… | Patch early | 9.8 critical | 10.4% | 2023-03-03 |
| CVE-2024-6127 | BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can… | Patch early | 9.8 critical | 10.3% | 2024-06-27 |
| CVE-2023-20079 | Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute a… | Patch early | 9.8 critical | 10.3% | 2023-03-03 |
| CVE-2016-5018 | In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able t… | Patch early | 9.1 critical | 10.3% | 2017-08-10 |
| CVE-2018-7364 | All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper… | Patch early | 9.8 critical | 10.3% | 2018-12-07 |
| CVE-2025-50165 | Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | Patch early | 9.8 critical | 10.3% | 2025-08-12 |
| CVE-2022-23747 | In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during mus… | Patch early | 9.8 critical | 10.2% | 2022-08-17 |
| CVE-2015-7182 | Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefo… | Patch early | 9.8 critical | 10.2% | 2015-11-05 |
| CVE-2016-1995 | HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors. | Patch early | 9.8 critical | 10.2% | 2016-03-18 |
| CVE-2017-8956 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | Patch early | 9.8 critical | 10.2% | 2018-02-15 |
| CVE-2019-17626 | ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<spa… | Patch early | 9.8 critical | 10.2% | 2019-10-16 |
| CVE-2016-0639 | Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote attackers to affect confidentiality, integrity, and… | Patch early | 9.8 critical | 10.2% | 2016-04-21 |
| CVE-2018-13338 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter du… | Patch early | 9.8 critical | 10.2% | 2018-11-27 |
| CVE-2019-7964 | Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation could lead to remote code executio… | Patch early | 9.8 critical | 10.2% | 2019-08-16 |
| CVE-2016-7406 | Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) u… | Patch early | 9.8 critical | 10.2% | 2017-03-03 |
| CVE-2018-7183 | Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an n… | Patch early | 9.8 critical | 10.2% | 2018-03-08 |
| CVE-2016-10150 | Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to… | Patch early | 9.8 critical | 10.2% | 2017-02-06 |
| CVE-2025-55754 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log mess… | Patch early | 9.6 critical | 10.2% | 2025-10-27 |
| CVE-2022-0592 | The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to… | Patch early | 9.8 critical | 10.2% | 2022-05-09 |
| CVE-2024-4295 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and inclu… | Patch early | 9.8 critical | 10.2% | 2024-06-05 |
| CVE-2022-32386 | Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan. | Patch early | 9.8 critical | 10.2% | 2022-07-06 |
| CVE-2008-0062 | KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service… | Patch early | 9.8 critical | 10.1% | 2008-03-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt