CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,371 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,713 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-6704 | An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to… | In your normal cycle | 9.8 critical | 9.5% | 2025-07-21 |
| CVE-2021-40720 | Ops CLI version 2.0.4 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary code execution when the chec… | In your normal cycle | 9.8 critical | 9.5% | 2021-10-15 |
| CVE-2017-11767 | ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects in… | In your normal cycle | 9.8 critical | 9.5% | 2017-11-02 |
| CVE-2017-3059 | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the internal script object. Successful exploita… | In your normal cycle | 9.8 critical | 9.5% | 2017-04-12 |
| CVE-2017-3062 | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter pro… | In your normal cycle | 9.8 critical | 9.5% | 2017-04-12 |
| CVE-2019-19649 | Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the Sy… | In your normal cycle | 9.8 critical | 9.5% | 2019-12-11 |
| CVE-2019-11678 | The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection. | In your normal cycle | 9.8 critical | 9.5% | 2019-05-02 |
| CVE-2025-42928 | Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch remote code execution. The sy… | In your normal cycle | 9.1 critical | 9.5% | 2025-12-09 |
| CVE-2020-8868 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not r… | In your normal cycle | 9.8 critical | 9.5% | 2020-03-23 |
| CVE-2018-20019 | LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can re… | In your normal cycle | 9.8 critical | 9.5% | 2018-12-19 |
| CVE-2018-12784 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Buffer Errors vulnerab… | In your normal cycle | 9.8 critical | 9.5% | 2018-07-20 |
| CVE-2019-0228 | Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attack… | In your normal cycle | 9.8 critical | 9.5% | 2019-04-17 |
| CVE-2013-5613 | Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbi… | In your normal cycle | 9.8 critical | 9.4% | 2013-12-11 |
| CVE-2017-14064 | Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using str… | In your normal cycle | 9.8 critical | 9.4% | 2017-08-31 |
| CVE-2019-7804 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earli… | In your normal cycle | 9.8 critical | 9.4% | 2019-05-22 |
| CVE-2022-0885 | The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing u… | In your normal cycle | 9.8 critical | 9.4% | 2022-06-13 |
| CVE-2019-17574 | An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the… | In your normal cycle | 9.1 critical | 9.4% | 2019-10-14 |
| CVE-2019-9641 | An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exi… | In your normal cycle | 9.8 critical | 9.4% | 2019-03-09 |
| CVE-2021-36745 | A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and S… | In your normal cycle | 9.8 critical | 9.4% | 2021-09-29 |
| CVE-2025-4918 | An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Fire… | In your normal cycle | 9.8 critical | 9.4% | 2025-05-17 |
| CVE-2019-11677 | The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection… | In your normal cycle | 9.8 critical | 9.4% | 2019-05-02 |
| CVE-2018-1000140 | rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result i… | In your normal cycle | 9.8 critical | 9.3% | 2018-03-23 |
| CVE-2018-14600 | An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, result… | In your normal cycle | 9.8 critical | 9.3% | 2018-08-24 |
| CVE-2013-4658 | Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share. | In your normal cycle | 9.8 critical | 9.3% | 2019-10-25 |
| CVE-2020-28026 | Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (… | In your normal cycle | 9.8 critical | 9.3% | 2021-05-06 |
| CVE-2020-13159 | Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Ali… | In your normal cycle | 9.8 critical | 9.3% | 2020-06-22 |
| CVE-2019-9023 | An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read… | In your normal cycle | 9.8 critical | 9.3% | 2019-02-22 |
| CVE-2017-2973 | Adobe Digital Editions versions 4.5.3 and earlier have an exploitable heap overflow vulnerability. Successful exploitation could lead to arbitrary cod… | In your normal cycle | 9.8 critical | 9.3% | 2017-02-15 |
| CVE-2020-10881 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 router… | In your normal cycle | 9.8 critical | 9.3% | 2020-03-25 |
| CVE-2025-0247 | Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough… | In your normal cycle | 9.8 critical | 9.3% | 2025-01-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt