CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,371 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,713 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-10972 | The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. | In your normal cycle | 9.8 critical | 9.3% | 2019-09-16 |
| CVE-2016-5773 | php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementatio… | In your normal cycle | 9.8 critical | 9.3% | 2016-08-07 |
| CVE-2019-11873 | wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size. An attacker sen… | In your normal cycle | 9.8 critical | 9.2% | 2019-05-23 |
| CVE-2020-6142 | A remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can cause local f… | In your normal cycle | 9.8 critical | 9.2% | 2020-09-01 |
| CVE-2015-8787 | The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of servi… | In your normal cycle | 9.8 critical | 9.2% | 2016-02-08 |
| CVE-2017-16725 | A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-based… | In your normal cycle | 9.8 critical | 9.2% | 2017-12-20 |
| CVE-2022-3180 | The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers… | In your normal cycle | 9.8 critical | 9.2% | 2025-02-11 |
| CVE-2026-28517 | openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves t… | In your normal cycle | 9.8 critical | 9.2% | 2026-02-27 |
| CVE-2020-11800 | Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code. | In your normal cycle | 9.8 critical | 9.2% | 2020-10-07 |
| CVE-2021-41419 | QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization. | In your normal cycle | 9.8 critical | 9.2% | 2022-07-18 |
| CVE-2018-5337 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existi… | In your normal cycle | 9.8 critical | 9.2% | 2018-04-18 |
| CVE-2017-16398 | An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earl… | In your normal cycle | 9.8 critical | 9.2% | 2017-12-09 |
| CVE-2015-3210 | Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expressio… | In your normal cycle | 9.8 critical | 9.2% | 2016-12-13 |
| CVE-2021-26937 | encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly h… | In your normal cycle | 9.8 critical | 9.1% | 2021-02-09 |
| CVE-2022-0814 | The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL state… | In your normal cycle | 9.8 critical | 9.1% | 2022-05-09 |
| CVE-2020-11897 | The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets. | In your normal cycle | 10.0 critical | 9.1% | 2020-06-17 |
| CVE-2022-26013 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_dmdsetHandler.ashx. This a… | In your normal cycle | 9.8 critical | 9.1% | 2022-03-29 |
| CVE-2022-25434 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg function. | In your normal cycle | 9.8 critical | 9.1% | 2022-03-18 |
| CVE-2021-43779 | GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from… | In your normal cycle | 9.9 critical | 9.1% | 2022-01-05 |
| CVE-2022-0826 | The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, le… | In your normal cycle | 9.8 critical | 9.1% | 2022-05-09 |
| CVE-2022-0827 | The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, lea… | In your normal cycle | 9.8 critical | 9.1% | 2022-06-13 |
| CVE-2016-0729 | Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C bef… | In your normal cycle | 9.8 critical | 9.1% | 2016-04-07 |
| CVE-2020-28901 | Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt componen… | In your normal cycle | 9.8 critical | 9.1% | 2021-05-24 |
| CVE-2020-11514 | The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the abil… | In your normal cycle | 9.8 critical | 9.1% | 2020-04-07 |
| CVE-2016-1558 | Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP-… | In your normal cycle | 9.8 critical | 9.1% | 2017-04-21 |
| CVE-2018-13336 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during… | In your normal cycle | 9.8 critical | 9.1% | 2018-11-27 |
| CVE-2004-1363 | Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are ex… | In your normal cycle | 9.8 critical | 9.1% | 2004-08-04 |
| CVE-2019-7095 | Adobe Digital Editions versions 4.5.10.185749 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execu… | In your normal cycle | 9.8 critical | 9.1% | 2019-05-24 |
| CVE-2025-44005 | An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol au… | In your normal cycle | 10.0 critical | 9.1% | 2025-12-17 |
| CVE-2017-11293 | An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earl… | In your normal cycle | 9.8 critical | 9.1% | 2017-12-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt