CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,546 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,735 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-15607 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15608 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15609 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15610 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15613 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15614 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15615 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2023-31985 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept fu… | In your normal cycle | 9.8 critical | 8.1% | 2023-05-12 |
| CVE-2018-1000666 | GIG Technology NV JumpScale Portal 7 version before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb contains a CWE-78: Improper Neutralization of Spec… | In your normal cycle | 9.8 critical | 8.1% | 2018-09-06 |
| CVE-2021-37762 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution. | In your normal cycle | 9.8 critical | 8.1% | 2021-10-07 |
| CVE-2016-1453 | Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote… | In your normal cycle | 9.8 critical | 8.1% | 2016-10-06 |
| CVE-2020-28037 | is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might all… | In your normal cycle | 9.8 critical | 8.1% | 2020-11-02 |
| CVE-2022-29361 | Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request… | In your normal cycle | 9.8 critical | 8.1% | 2022-05-25 |
| CVE-2025-59934 | Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems… | In your normal cycle | 9.4 critical | 8.1% | 2025-09-26 |
| CVE-2017-11303 | An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable memory corruption vulnerability exists. Successful e… | In your normal cycle | 9.8 critical | 8.1% | 2017-12-09 |
| CVE-2021-32930 | The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arb… | In your normal cycle | 9.8 critical | 8.1% | 2021-06-11 |
| CVE-2020-4415 | IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote… | In your normal cycle | 9.8 critical | 8.1% | 2020-04-23 |
| CVE-2018-20664 | Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license. | In your normal cycle | 9.8 critical | 8.1% | 2019-01-03 |
| CVE-2026-58455 | Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell comma… | In your normal cycle | 9.8 critical | 8% | 2026-07-02 |
| CVE-2018-7124 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | In your normal cycle | 9.8 critical | 8% | 2019-06-05 |
| CVE-2019-5367 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | In your normal cycle | 9.8 critical | 8% | 2019-06-05 |
| CVE-2025-32711 | Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | In your normal cycle | 9.3 critical | 8% | 2025-06-11 |
| CVE-2018-12822 | Adobe Digital Editions versions 4.5.8 and below have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | In your normal cycle | 9.8 critical | 8% | 2018-10-17 |
| CVE-2018-16618 | VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttrans… | In your normal cycle | 9.8 critical | 8% | 2019-06-19 |
| CVE-2018-1000007 | libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcu… | In your normal cycle | 9.8 critical | 8% | 2018-01-24 |
| CVE-2025-53766 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | In your normal cycle | 9.8 critical | 8% | 2025-08-12 |
| CVE-2016-6809 | Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do… | In your normal cycle | 9.8 critical | 8% | 2017-04-06 |
| CVE-2022-1057 | The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL stateme… | In your normal cycle | 9.8 critical | 8% | 2022-07-11 |
| CVE-2021-41833 | Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution. | In your normal cycle | 9.8 critical | 8% | 2021-11-11 |
| CVE-2023-34152 | A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. | In your normal cycle | 9.8 critical | 8% | 2023-05-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt