CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,573 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,743 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-34513 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthe… | In your normal cycle | 9.8 critical | 7.6% | 2025-10-16 |
| CVE-2021-3331 | WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted URL that loads session settings.… | In your normal cycle | 9.8 critical | 7.6% | 2021-01-27 |
| CVE-2021-27708 | Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allow… | In your normal cycle | 9.8 critical | 7.6% | 2021-04-14 |
| CVE-2020-11656 | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT… | In your normal cycle | 9.8 critical | 7.6% | 2020-04-09 |
| CVE-2024-38652 | Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via ar… | In your normal cycle | 9.1 critical | 7.6% | 2024-08-14 |
| CVE-2025-55591 | TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoin… | In your normal cycle | 9.8 critical | 7.6% | 2025-08-18 |
| CVE-2020-20601 | An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet. | In your normal cycle | 9.8 critical | 7.6% | 2021-12-22 |
| CVE-2016-10164 | Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cau… | In your normal cycle | 9.8 critical | 7.6% | 2017-02-01 |
| CVE-2019-1222 | A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne… | In your normal cycle | 9.8 critical | 7.6% | 2019-08-14 |
| CVE-2020-3805 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and… | In your normal cycle | 9.8 critical | 7.6% | 2020-03-25 |
| CVE-2022-0783 | The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in S… | In your normal cycle | 9.8 critical | 7.6% | 2022-05-02 |
| CVE-2016-0859 | Integer overflow in the Kernel service in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of servic… | In your normal cycle | 9.8 critical | 7.6% | 2016-01-15 |
| CVE-2017-9120 | PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other… | In your normal cycle | 9.8 critical | 7.6% | 2018-08-02 |
| CVE-2020-9633 | Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, and Adobe Flash Player for Mic… | In your normal cycle | 9.8 critical | 7.6% | 2020-06-12 |
| CVE-2016-9841 | inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | In your normal cycle | 9.8 critical | 7.6% | 2017-05-23 |
| CVE-2019-11683 | udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out… | In your normal cycle | 9.8 critical | 7.6% | 2019-05-02 |
| CVE-2026-48030 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in… | In your normal cycle | 9.9 critical | 7.5% | 2026-07-27 |
| CVE-2017-11366 | components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded i… | In your normal cycle | 9.8 critical | 7.5% | 2017-08-21 |
| CVE-2016-4107 | Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Ac… | In your normal cycle | 9.8 critical | 7.5% | 2016-05-11 |
| CVE-2016-0088 | Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a… | In your normal cycle | 9.3 critical | 7.5% | 2016-04-12 |
| CVE-2018-19442 | A Buffer Overflow in Network::AuthenticationClient::VerifySignature in /bin/astro in Neato Botvac Connected 2.2.0 allows a remote attacker to execute… | In your normal cycle | 9.8 critical | 7.5% | 2019-04-25 |
| CVE-2018-14720 | FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecif… | In your normal cycle | 9.8 critical | 7.5% | 2019-01-02 |
| CVE-2026-56274 | Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation… | In your normal cycle | 9.9 critical | 7.5% | 2026-06-23 |
| CVE-2019-14985 | eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface,… | In your normal cycle | 9.8 critical | 7.5% | 2019-08-13 |
| CVE-2020-3718 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful… | In your normal cycle | 9.8 critical | 7.5% | 2020-01-29 |
| CVE-2021-43510 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php. | In your normal cycle | 9.8 critical | 7.5% | 2022-02-01 |
| CVE-2020-36849 | The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-content/plugins/… | In your normal cycle | 9.8 critical | 7.5% | 2025-07-12 |
| CVE-2018-12808 | Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier have an out-of-bounds write v… | In your normal cycle | 9.8 critical | 7.5% | 2018-08-29 |
| CVE-2017-9226 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds wri… | In your normal cycle | 9.8 critical | 7.5% | 2017-05-24 |
| CVE-2018-8319 | A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka "MSR Ja… | In your normal cycle | 9.8 critical | 7.5% | 2018-07-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt