CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,620 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,745 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-3760 | Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code executio… | In your normal cycle | 9.8 critical | 7.2% | 2020-02-13 |
| CVE-2022-25488 | Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php. | In your normal cycle | 9.8 critical | 7.1% | 2022-03-15 |
| CVE-2016-10243 | TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file. | In your normal cycle | 9.8 critical | 7.1% | 2017-05-02 |
| CVE-2020-3794 | ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code exe… | In your normal cycle | 9.8 critical | 7.1% | 2020-03-25 |
| CVE-2018-12825 | Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass. | In your normal cycle | 9.8 critical | 7.1% | 2018-08-29 |
| CVE-2018-12828 | Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to… | In your normal cycle | 9.8 critical | 7.1% | 2018-08-29 |
| CVE-2016-8204 | A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow r… | In your normal cycle | 9.8 critical | 7.1% | 2017-01-14 |
| CVE-2021-42784 | OS Command Injection vulnerability in debug_fcgi of D-Link DWR-932C E1 firmware allows a remote attacker to perform command injection via a crafted HT… | In your normal cycle | 9.8 critical | 7.1% | 2021-11-23 |
| CVE-2017-3097 | Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loadin… | In your normal cycle | 9.8 critical | 7.1% | 2017-06-20 |
| CVE-2015-5344 | The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted… | In your normal cycle | 9.8 critical | 7.1% | 2016-02-03 |
| CVE-2015-7669 | Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 f… | In your normal cycle | 9.8 critical | 7.1% | 2017-12-27 |
| CVE-2024-9989 | The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is due to a limited arbitrary meth… | In your normal cycle | 9.8 critical | 7.1% | 2024-10-29 |
| CVE-2021-26293 | An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to creat… | In your normal cycle | 9.8 critical | 7.1% | 2021-03-04 |
| CVE-2021-40371 | Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\\ in a s… | In your normal cycle | 9.8 critical | 7.1% | 2021-10-25 |
| CVE-2026-8985 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthent… | In your normal cycle | 9.8 critical | 7.1% | 2026-07-21 |
| CVE-2016-4073 | Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x befo… | In your normal cycle | 9.8 critical | 7.1% | 2016-05-20 |
| CVE-2016-5229 | Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers t… | In your normal cycle | 9.8 critical | 7.1% | 2016-08-02 |
| CVE-2018-4995 | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an XFA '\n' POST injecti… | In your normal cycle | 9.8 critical | 7.1% | 2018-07-09 |
| CVE-2015-0782 | SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attacker… | In your normal cycle | 9.8 critical | 7.1% | 2017-08-09 |
| CVE-2024-23476 | The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, thi… | In your normal cycle | 9.6 critical | 7.1% | 2024-02-15 |
| CVE-2020-37125 | Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands thro… | In your normal cycle | 9.8 critical | 7.1% | 2026-02-05 |
| CVE-2002-1347 | Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary c… | In your normal cycle | 9.8 critical | 7.1% | 2002-12-18 |
| CVE-2020-12832 | WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to… | In your normal cycle | 9.8 critical | 7.1% | 2020-05-13 |
| CVE-2014-1486 | Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, an… | In your normal cycle | 9.8 critical | 7.1% | 2014-02-06 |
| CVE-2017-5336 | Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote atta… | In your normal cycle | 9.8 critical | 7.1% | 2017-03-24 |
| CVE-2018-5102 | A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This… | In your normal cycle | 9.8 critical | 7.1% | 2018-06-11 |
| CVE-2017-11304 | An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable use-after-free vulnerability exists. Successful expl… | In your normal cycle | 9.8 critical | 7.1% | 2017-12-09 |
| CVE-2019-19919 | Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto_… | In your normal cycle | 9.8 critical | 7.1% | 2019-12-20 |
| CVE-2019-8395 | An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment… | In your normal cycle | 9.8 critical | 7.1% | 2019-02-17 |
| CVE-2021-33026 | The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege es… | In your normal cycle | 9.8 critical | 7.1% | 2021-05-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt