CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,732 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-24666 | The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest rou… | In your normal cycle | 9.8 critical | 8.9% | 2021-09-27 |
| CVE-2015-8841 | Heap-based buffer overflow in the Archive support module in ESET NOD32 before update 11861 allows remote attackers to execute arbitrary code via a lar… | In your normal cycle | 9.8 critical | 8.9% | 2016-04-12 |
| CVE-2020-10257 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PH… | In your normal cycle | 9.8 critical | 8.9% | 2020-03-10 |
| CVE-2018-7103 | A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manager Software earlier than versio… | In your normal cycle | 9.8 critical | 8.9% | 2018-09-27 |
| CVE-2018-7104 | A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manager Software earlier than versio… | In your normal cycle | 9.8 critical | 8.9% | 2018-09-27 |
| CVE-2018-12785 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerab… | In your normal cycle | 9.8 critical | 8.9% | 2018-07-20 |
| CVE-2023-50469 | Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 was discovered to contain a buffer overflow via the ApCliEncrypType parameter at /apply.cg… | In your normal cycle | 9.8 critical | 8.9% | 2023-12-15 |
| CVE-2016-0746 | Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of servic… | In your normal cycle | 9.8 critical | 8.9% | 2016-02-15 |
| CVE-2016-3499 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3.0 and 12.2.1.0 allows remote attackers to affect… | In your normal cycle | 9.8 critical | 8.9% | 2016-07-21 |
| CVE-2022-20473 | In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execu… | In your normal cycle | 9.8 critical | 8.9% | 2022-12-13 |
| CVE-2016-1114 | Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted… | In your normal cycle | 9.8 critical | 8.8% | 2016-05-11 |
| CVE-2018-4996 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… | In your normal cycle | 9.8 critical | 8.8% | 2018-07-09 |
| CVE-2017-11294 | An issue was discovered in Adobe Shockwave 12.2.9.199 and earlier. An exploitable memory corruption vulnerability exists. Successful exploitation coul… | In your normal cycle | 9.8 critical | 8.8% | 2017-12-09 |
| CVE-2021-22989 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x be… | In your normal cycle | 9.1 critical | 8.8% | 2021-03-31 |
| CVE-2020-27995 | SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do templat… | In your normal cycle | 9.8 critical | 8.8% | 2020-10-29 |
| CVE-2016-7126 | The imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate the number of colors, which… | In your normal cycle | 9.8 critical | 8.8% | 2016-09-12 |
| CVE-2019-7482 | Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability imp… | In your normal cycle | 9.8 critical | 8.8% | 2019-12-19 |
| CVE-2019-9636 | Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normali… | In your normal cycle | 9.8 critical | 8.8% | 2019-03-08 |
| CVE-2016-9369 | An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.… | In your normal cycle | 9.8 critical | 8.8% | 2017-02-13 |
| CVE-2018-17190 | In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' host… | In your normal cycle | 9.8 critical | 8.8% | 2018-11-19 |
| CVE-2022-0846 | The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via t… | In your normal cycle | 9.8 critical | 8.8% | 2022-03-28 |
| CVE-2019-13278 | TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, al… | In your normal cycle | 9.8 critical | 8.8% | 2019-07-10 |
| CVE-2016-6354 | Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of servic… | In your normal cycle | 9.8 critical | 8.8% | 2016-09-21 |
| CVE-2019-11223 | An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by… | In your normal cycle | 9.8 critical | 8.8% | 2019-04-18 |
| CVE-2019-10071 | The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the… | In your normal cycle | 9.8 critical | 8.8% | 2019-09-16 |
| CVE-2020-20300 | SQL injection vulnerability in the wp_where function in WeiPHP 5.0. | In your normal cycle | 9.8 critical | 8.8% | 2020-12-18 |
| CVE-2023-31902 | RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE). | In your normal cycle | 9.8 critical | 8.7% | 2023-05-17 |
| CVE-2016-10182 | An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters. | In your normal cycle | 9.8 critical | 8.7% | 2017-01-30 |
| CVE-2019-16199 | eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface v… | In your normal cycle | 9.8 critical | 8.7% | 2019-09-17 |
| CVE-2024-24578 | RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 con… | In your normal cycle | 10.0 critical | 8.7% | 2024-03-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt