CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,522 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,734 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-10989 | In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation of the leng… | In your normal cycle | 9.8 critical | 8.6% | 2019-06-28 |
| CVE-2021-30175 | ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page. | In your normal cycle | 9.8 critical | 8.5% | 2021-04-13 |
| CVE-2020-15636 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R6400, R6700, R7000, R7850, R7900, R8000, RS… | In your normal cycle | 9.8 critical | 8.5% | 2020-08-20 |
| CVE-2017-13208 | In receive_packet of libnetutils/packet.c, there is a possible out-of-bounds write due to a missing bounds check on the DHCP response. This could lead… | In your normal cycle | 9.8 critical | 8.5% | 2018-01-12 |
| CVE-2015-9235 | In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (R… | In your normal cycle | 9.8 critical | 8.5% | 2018-05-29 |
| CVE-2017-8816 | The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow… | In your normal cycle | 9.8 critical | 8.5% | 2017-11-29 |
| CVE-2022-20130 | In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote cod… | In your normal cycle | 9.8 critical | 8.5% | 2022-06-15 |
| CVE-2016-6939 | Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acro… | In your normal cycle | 9.8 critical | 8.5% | 2016-10-13 |
| CVE-2017-3090 | Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loadin… | In your normal cycle | 9.8 critical | 8.5% | 2017-06-20 |
| CVE-2017-3092 | Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loadin… | In your normal cycle | 9.8 critical | 8.5% | 2017-06-20 |
| CVE-2024-34544 | A command injection vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP req… | In your normal cycle | 9.1 critical | 8.5% | 2025-01-14 |
| CVE-2016-0749 | The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code vi… | In your normal cycle | 9.8 critical | 8.5% | 2016-06-09 |
| CVE-2025-7624 | An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code… | In your normal cycle | 9.8 critical | 8.5% | 2025-07-21 |
| CVE-2025-29268 | ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library. | In your normal cycle | 9.8 critical | 8.5% | 2025-12-04 |
| CVE-2016-8863 | Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attack… | In your normal cycle | 9.8 critical | 8.5% | 2017-03-07 |
| CVE-2016-7954 | Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source.… | In your normal cycle | 9.8 critical | 8.5% | 2016-12-22 |
| CVE-2021-24849 | The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does… | In your normal cycle | 9.8 critical | 8.5% | 2021-12-21 |
| CVE-2019-10880 | Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" requ… | In your normal cycle | 9.8 critical | 8.5% | 2019-04-12 |
| CVE-2020-4589 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted… | In your normal cycle | 9.8 critical | 8.5% | 2020-08-13 |
| CVE-2016-6793 | The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop)… | In your normal cycle | 9.1 critical | 8.5% | 2017-07-17 |
| CVE-2023-51091 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler. | In your normal cycle | 9.8 critical | 8.5% | 2023-12-26 |
| CVE-2020-36155 | An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker… | In your normal cycle | 10.0 critical | 8.5% | 2021-01-04 |
| CVE-2026-0768 | Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins… | In your normal cycle | 9.8 critical | 8.5% | 2026-01-23 |
| CVE-2018-1151 | The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers to execute arbitrary code or… | In your normal cycle | 9.8 critical | 8.4% | 2018-06-12 |
| CVE-2021-2135 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Supported versions that are affected… | In your normal cycle | 9.8 critical | 8.4% | 2021-04-22 |
| CVE-2019-13561 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_ch… | In your normal cycle | 9.8 critical | 8.4% | 2019-07-11 |
| CVE-2016-3191 | The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*AC… | In your normal cycle | 9.8 critical | 8.4% | 2016-03-17 |
| CVE-2026-33439 | Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Rem… | In your normal cycle | 9.8 critical | 8.4% | 2026-04-07 |
| CVE-2017-16613 | An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and p… | In your normal cycle | 9.8 critical | 8.4% | 2017-11-21 |
| CVE-2021-42670 | A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page.… | In your normal cycle | 9.8 critical | 8.4% | 2021-11-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt