CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,317 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,711 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-1297 | When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access t… | In your normal cycle | 9.8 critical | 9.9% | 2018-02-13 |
| CVE-2018-11066 | Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated… | In your normal cycle | 9.8 critical | 9.9% | 2018-11-26 |
| CVE-2020-14625 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0… | In your normal cycle | 9.8 critical | 9.9% | 2020-07-15 |
| CVE-2022-0948 | The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via… | In your normal cycle | 9.8 critical | 9.9% | 2022-05-09 |
| CVE-2025-69542 | A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease re… | In your normal cycle | 9.8 critical | 9.9% | 2026-01-09 |
| CVE-2017-14746 | Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request. | In your normal cycle | 9.8 critical | 9.9% | 2017-11-27 |
| CVE-2016-0779 | The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted se… | In your normal cycle | 9.8 critical | 9.9% | 2017-04-11 |
| CVE-2016-4091 | Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acro… | In your normal cycle | 9.8 critical | 9.9% | 2016-05-11 |
| CVE-2016-4092 | Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acro… | In your normal cycle | 9.8 critical | 9.9% | 2016-05-11 |
| CVE-2022-44366 | Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setDiagnoseInfo. | In your normal cycle | 9.8 critical | 9.9% | 2022-12-02 |
| CVE-2017-8994 | A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely. | In your normal cycle | 9.8 critical | 9.8% | 2017-10-10 |
| CVE-2023-46260 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… | In your normal cycle | 9.8 critical | 9.8% | 2023-12-19 |
| CVE-2022-38555 | Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name. | In your normal cycle | 9.8 critical | 9.8% | 2022-08-28 |
| CVE-2020-36178 | oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web int… | In your normal cycle | 9.8 critical | 9.8% | 2021-01-06 |
| CVE-2018-25120 | D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulnerability in the Mail Test funct… | In your normal cycle | 9.8 critical | 9.8% | 2025-10-29 |
| CVE-2017-9629 | A Stack-Based Buffer Overflow issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The stack-ba… | In your normal cycle | 9.8 critical | 9.8% | 2017-07-07 |
| CVE-2010-2076 | Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDD… | In your normal cycle | 9.8 critical | 9.8% | 2010-08-19 |
| CVE-2021-3193 | Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated at… | In your normal cycle | 9.8 critical | 9.8% | 2021-01-26 |
| CVE-2018-19716 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… | In your normal cycle | 9.8 critical | 9.7% | 2019-01-18 |
| CVE-2021-24215 | An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the websi… | In your normal cycle | 9.8 critical | 9.7% | 2021-04-12 |
| CVE-2017-0898 | Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such s… | In your normal cycle | 9.1 critical | 9.7% | 2017-09-15 |
| CVE-2018-8780 | In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empt… | In your normal cycle | 9.1 critical | 9.7% | 2018-04-03 |
| CVE-2014-3600 | XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving… | In your normal cycle | 9.8 critical | 9.7% | 2017-10-27 |
| CVE-2022-30512 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31. | In your normal cycle | 9.8 critical | 9.7% | 2022-06-02 |
| CVE-2024-37357 | A buffer overflow vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request… | In your normal cycle | 9.1 critical | 9.7% | 2025-01-14 |
| CVE-2002-0059 | The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory m… | In your normal cycle | 9.8 critical | 9.7% | 2002-03-15 |
| CVE-2021-1609 | Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Route… | In your normal cycle | 9.8 critical | 9.7% | 2021-08-04 |
| CVE-2024-9014 | pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obt… | In your normal cycle | 9.9 critical | 9.7% | 2024-09-23 |
| CVE-2018-14719 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and… | In your normal cycle | 9.8 critical | 9.7% | 2019-01-02 |
| CVE-2024-12106 | In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings. | In your normal cycle | 9.4 critical | 9.7% | 2024-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt