CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,620 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,745 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-10638 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflow vulnerabilities exist caused by a lack of proper… | In your normal cycle | 9.8 critical | 7.1% | 2020-05-08 |
| CVE-2024-28185 | Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the sandbox directory, which can be… | In your normal cycle | 10.0 critical | 7.1% | 2024-04-18 |
| CVE-2018-8793 | rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corruptio… | In your normal cycle | 9.8 critical | 7.1% | 2019-02-05 |
| CVE-2018-8797 | rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and… | In your normal cycle | 9.8 critical | 7.1% | 2019-02-05 |
| CVE-2018-8800 | rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruptio… | In your normal cycle | 9.8 critical | 7.1% | 2019-02-05 |
| CVE-2018-11236 | stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath functio… | In your normal cycle | 9.8 critical | 7.1% | 2018-05-18 |
| CVE-2018-12532 | JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execu… | In your normal cycle | 9.8 critical | 7% | 2018-06-18 |
| CVE-2016-4102 | Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Ac… | In your normal cycle | 9.8 critical | 7% | 2016-05-11 |
| CVE-2017-10979 | An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of servi… | In your normal cycle | 9.8 critical | 7% | 2017-07-17 |
| CVE-2016-4448 | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. | In your normal cycle | 9.8 critical | 7% | 2016-06-09 |
| CVE-2020-27976 | osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the applicati… | In your normal cycle | 9.8 critical | 7% | 2020-10-28 |
| CVE-2018-20056 | An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. There is a stack-based buffer overflow allowing… | In your normal cycle | 9.8 critical | 7% | 2018-12-11 |
| CVE-2022-20145 | In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to re… | In your normal cycle | 9.8 critical | 7% | 2022-06-15 |
| CVE-2018-8954 | CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request. | In your normal cycle | 9.8 critical | 7% | 2018-04-11 |
| CVE-2021-36394 | In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. | In your normal cycle | 9.8 critical | 7% | 2023-03-06 |
| CVE-2015-8833 | Use-after-free vulnerability in the create_smp_dialog function in gtk-dialog.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 4.0.2 fo… | In your normal cycle | 9.8 critical | 7% | 2016-04-12 |
| CVE-2025-68145 | In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository… | In your normal cycle | 9.1 critical | 7% | 2025-12-17 |
| CVE-2022-20127 | In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no addi… | In your normal cycle | 9.8 critical | 7% | 2022-06-15 |
| CVE-2019-11036 | When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past… | In your normal cycle | 9.1 critical | 7% | 2019-05-03 |
| CVE-2026-27175 | MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is i… | In your normal cycle | 9.8 critical | 7% | 2026-02-18 |
| CVE-2017-12621 | During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used i… | In your normal cycle | 9.8 critical | 7% | 2017-09-28 |
| CVE-2022-26651 | An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escapin… | In your normal cycle | 9.8 critical | 7% | 2022-04-15 |
| CVE-2021-44735 | Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07. | In your normal cycle | 9.8 critical | 7% | 2022-01-20 |
| CVE-2015-6490 | Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attackers… | In your normal cycle | 9.8 critical | 7% | 2015-10-28 |
| CVE-2021-26893 | Windows DNS Server Remote Code Execution Vulnerability | In your normal cycle | 9.8 critical | 7% | 2021-03-11 |
| CVE-2020-14505 | Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Suc… | In your normal cycle | 9.8 critical | 7% | 2020-07-15 |
| CVE-2020-24646 | A tftpserver stack-based buffer overflow remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Pri… | In your normal cycle | 9.8 critical | 7% | 2020-10-19 |
| CVE-2021-40175 | Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution. | In your normal cycle | 9.8 critical | 7% | 2021-08-29 |
| CVE-2019-14514 | An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu emulator contains a /system/bi… | In your normal cycle | 9.8 critical | 7% | 2020-02-11 |
| CVE-2020-17441 | An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 headers does not validate whether the IPv6 payload length field is equal to… | In your normal cycle | 9.1 critical | 7% | 2020-12-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt