CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,573 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,743 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-5929 | QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components. | In your normal cycle | 9.8 critical | 7.5% | 2017-03-13 |
| CVE-2020-27158 | Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.… | In your normal cycle | 9.8 critical | 7.5% | 2020-10-27 |
| CVE-2016-3607 | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect confi… | In your normal cycle | 9.8 critical | 7.5% | 2016-07-21 |
| CVE-2021-34074 | PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a rela… | In your normal cycle | 9.8 critical | 7.5% | 2021-06-25 |
| CVE-2022-1013 | The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL sta… | In your normal cycle | 9.8 critical | 7.5% | 2022-05-09 |
| CVE-2018-11228 | Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution… | In your normal cycle | 9.8 critical | 7.5% | 2018-06-08 |
| CVE-2021-42002 | Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution. | In your normal cycle | 9.8 critical | 7.5% | 2021-11-11 |
| CVE-2024-5655 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting f… | In your normal cycle | 9.6 critical | 7.5% | 2024-06-27 |
| CVE-2019-5481 | Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. | In your normal cycle | 9.8 critical | 7.5% | 2019-09-16 |
| CVE-2016-10191 | Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows rem… | In your normal cycle | 9.8 critical | 7.5% | 2017-02-09 |
| CVE-2018-11757 | In Docker Skeleton Runtime for Apache OpenWhisk, a Docker action inheriting the Docker tag openwhisk/dockerskeleton:1.3.0 (or earlier) may allow an at… | In your normal cycle | 9.8 critical | 7.5% | 2018-07-23 |
| CVE-2018-19988 | In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.B… | In your normal cycle | 9.8 critical | 7.4% | 2019-05-13 |
| CVE-2017-12932 | ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free while unserializing untrusted d… | In your normal cycle | 9.8 critical | 7.4% | 2017-08-18 |
| CVE-2016-4629 | ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted xS… | In your normal cycle | 9.8 critical | 7.4% | 2016-07-22 |
| CVE-2017-3222 | Hard-coded credentials in AmosConnect 8 allow remote attackers to gain full administrative privileges, including the ability to execute commands on th… | In your normal cycle | 9.8 critical | 7.4% | 2017-07-22 |
| CVE-2009-1120 | EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability. The flaw exists within the DoRcvRpcCall RPC fun… | In your normal cycle | 9.8 critical | 7.4% | 2020-01-15 |
| CVE-2019-17059 | A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitr… | In your normal cycle | 9.8 critical | 7.4% | 2019-10-11 |
| CVE-2020-11552 | An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileg… | In your normal cycle | 9.8 critical | 7.4% | 2020-08-11 |
| CVE-2023-29234 | A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through… | In your normal cycle | 9.8 critical | 7.4% | 2023-12-15 |
| CVE-2018-8788 | FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption a… | In your normal cycle | 9.8 critical | 7.4% | 2018-11-29 |
| CVE-2018-8795 | rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_updates… | In your normal cycle | 9.8 critical | 7.4% | 2019-02-05 |
| CVE-2020-9631 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vul… | In your normal cycle | 9.8 critical | 7.4% | 2020-06-26 |
| CVE-2020-9632 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vul… | In your normal cycle | 9.8 critical | 7.4% | 2020-06-26 |
| CVE-2016-1050 | Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Ac… | In your normal cycle | 9.8 critical | 7.4% | 2016-05-11 |
| CVE-2016-10160 | Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause… | In your normal cycle | 9.8 critical | 7.4% | 2017-01-24 |
| CVE-2018-17064 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fun… | In your normal cycle | 9.8 critical | 7.4% | 2018-09-15 |
| CVE-2021-20110 | Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP addre… | In your normal cycle | 9.8 critical | 7.4% | 2021-07-19 |
| CVE-2017-9328 | Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as ro… | In your normal cycle | 9.8 critical | 7.4% | 2017-09-15 |
| CVE-2019-12272 | In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application ar… | In your normal cycle | 9.8 critical | 7.4% | 2019-05-23 |
| CVE-2026-41679 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated at… | In your normal cycle | 10.0 critical | 7.4% | 2026-04-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt