CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,957 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,763 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-21642 | Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attacker… | In your normal cycle | 9.8 critical | 7% | 2022-08-15 |
| CVE-2016-9935 | The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service… | In your normal cycle | 9.8 critical | 7% | 2017-01-04 |
| CVE-2025-55583 | D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component.… | In your normal cycle | 9.8 critical | 7% | 2025-08-28 |
| CVE-2015-2868 | An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can conne… | In your normal cycle | 9.8 critical | 7% | 2017-01-06 |
| CVE-2020-15541 | SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution. | In your normal cycle | 9.8 critical | 7% | 2020-07-05 |
| CVE-2020-0690 | An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. | In your normal cycle | 9.8 critical | 7% | 2020-03-12 |
| CVE-2016-1038 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 10.0 critical | 7% | 2016-05-11 |
| CVE-2025-63207 | The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication ch… | In your normal cycle | 9.8 critical | 7% | 2025-11-19 |
| CVE-2018-11219 | An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2,… | In your normal cycle | 9.8 critical | 7% | 2018-06-17 |
| CVE-1999-0511 | IP forwarding is enabled on a machine which is not a router or firewall. | In your normal cycle | 9.1 critical | 7% | 1997-01-01 |
| CVE-2016-4303 | The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (cras… | In your normal cycle | 9.8 critical | 7% | 2016-09-26 |
| CVE-2019-4087 | IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by ser… | In your normal cycle | 9.8 critical | 7% | 2019-07-02 |
| CVE-2013-5017 | SNMPConfig.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote attackers to execute arbitrary commands via unspecif… | In your normal cycle | 9.8 critical | 7% | 2014-06-18 |
| CVE-2017-14350 | A potential security vulnerability has been identified in HPE Application Performance Management (BSM) Platform versions 9.26, 9.30, 9.40. The vulnera… | In your normal cycle | 9.8 critical | 7% | 2017-09-30 |
| CVE-2023-3452 | The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This all… | In your normal cycle | 9.8 critical | 7% | 2023-08-12 |
| CVE-2019-3930 | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W befor… | In your normal cycle | 9.8 critical | 7% | 2019-04-30 |
| CVE-2023-48792 | Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option. | In your normal cycle | 9.8 critical | 7% | 2024-02-02 |
| CVE-2023-48793 | Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature. | In your normal cycle | 9.8 critical | 7% | 2024-02-02 |
| CVE-2018-6231 | A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could a… | In your normal cycle | 9.8 critical | 6.9% | 2018-03-15 |
| CVE-2020-3280 | A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote a… | In your normal cycle | 9.8 critical | 6.9% | 2020-05-22 |
| CVE-2017-12933 | The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a bu… | In your normal cycle | 9.8 critical | 6.9% | 2017-08-18 |
| CVE-2016-10177 | An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root w… | In your normal cycle | 9.8 critical | 6.9% | 2017-01-30 |
| CVE-2017-3098 | Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and write… | In your normal cycle | 9.8 critical | 6.9% | 2017-06-20 |
| CVE-2020-5757 | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can b… | In your normal cycle | 9.8 critical | 6.9% | 2020-07-17 |
| CVE-2019-3479 | Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7. | In your normal cycle | 9.8 critical | 6.9% | 2019-03-25 |
| CVE-2022-1453 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied da… | In your normal cycle | 9.8 critical | 6.9% | 2022-05-10 |
| CVE-2022-0693 | The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (av… | In your normal cycle | 9.8 critical | 6.9% | 2022-04-25 |
| CVE-2025-20363 | A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) So… | In your normal cycle | 9.0 critical | 6.9% | 2025-09-25 |
| CVE-2022-29776 | Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/co… | In your normal cycle | 9.8 critical | 6.9% | 2022-06-02 |
| CVE-2022-29777 | Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fon… | In your normal cycle | 9.8 critical | 6.9% | 2022-06-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt