CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,488 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,732 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-3466 | A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attack… | In your normal cycle | 9.8 critical | 8.7% | 2021-03-25 |
| CVE-2018-12756 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnera… | In your normal cycle | 9.8 critical | 8.7% | 2018-07-20 |
| CVE-2018-12802 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Security Bypass vulner… | In your normal cycle | 9.8 critical | 8.7% | 2018-07-20 |
| CVE-2020-7593 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.01), LOGO!… | In your normal cycle | 9.8 critical | 8.7% | 2020-07-14 |
| CVE-2017-11274 | Adobe Digital Editions 4.5.4 and earlier has an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code executi… | In your normal cycle | 9.8 critical | 8.7% | 2017-08-11 |
| CVE-2017-3075 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability when manipulating the ActionsScript 2 XML class. S… | In your normal cycle | 9.8 critical | 8.7% | 2017-06-20 |
| CVE-2017-3084 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the advertising metadata functionality. Success… | In your normal cycle | 9.8 critical | 8.7% | 2017-06-20 |
| CVE-2017-3853 | A vulnerability in the Data-in-Motion (DMo) process installed with the Cisco IOx application environment could allow an unauthenticated, remote attack… | In your normal cycle | 9.8 critical | 8.7% | 2017-03-22 |
| CVE-2016-6938 | Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Ac… | In your normal cycle | 9.8 critical | 8.7% | 2016-09-17 |
| CVE-2017-8981 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found. | In your normal cycle | 9.8 critical | 8.7% | 2018-02-15 |
| CVE-2021-26291 | Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting i… | In your normal cycle | 9.1 critical | 8.7% | 2021-04-23 |
| CVE-2022-20140 | In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of pri… | In your normal cycle | 9.8 critical | 8.7% | 2022-06-15 |
| CVE-2015-6435 | An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5… | In your normal cycle | 9.8 critical | 8.7% | 2016-01-22 |
| CVE-2018-5338 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanis… | In your normal cycle | 9.8 critical | 8.7% | 2018-04-18 |
| CVE-2025-2620 | A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler… | In your normal cycle | 9.8 critical | 8.7% | 2025-03-22 |
| CVE-2023-39747 | TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSecret parameter at /userRpm/Wla… | In your normal cycle | 9.8 critical | 8.7% | 2023-08-21 |
| CVE-2023-39751 | TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm. | In your normal cycle | 9.8 critical | 8.7% | 2023-08-21 |
| CVE-2024-30163 | Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_c… | In your normal cycle | 9.8 critical | 8.7% | 2024-06-07 |
| CVE-2019-14896 | A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could… | In your normal cycle | 9.8 critical | 8.7% | 2019-11-27 |
| CVE-2022-35649 | The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in… | In your normal cycle | 9.8 critical | 8.7% | 2022-07-25 |
| CVE-2023-46977 | TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth. | In your normal cycle | 9.8 critical | 8.7% | 2023-10-31 |
| CVE-2017-5814 | A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found. | In your normal cycle | 9.8 critical | 8.7% | 2018-02-15 |
| CVE-2020-25483 | An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the se… | In your normal cycle | 9.8 critical | 8.7% | 2020-10-23 |
| CVE-2020-25367 | A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to exec… | In your normal cycle | 9.8 critical | 8.6% | 2021-11-04 |
| CVE-2020-25368 | A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to exec… | In your normal cycle | 9.8 critical | 8.6% | 2021-11-04 |
| CVE-2019-20330 | FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. | In your normal cycle | 9.8 critical | 8.6% | 2020-01-03 |
| CVE-2022-0658 | The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to un… | In your normal cycle | 9.8 critical | 8.6% | 2022-03-14 |
| CVE-2022-0787 | The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statement… | In your normal cycle | 9.8 critical | 8.6% | 2022-03-28 |
| CVE-2018-4944 | Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary c… | In your normal cycle | 9.8 critical | 8.6% | 2018-05-19 |
| CVE-2016-1000112 | Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin | In your normal cycle | 9.1 critical | 8.6% | 2016-10-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt