CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,957 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,763 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-1044 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 10.0 critical | 6.9% | 2016-05-11 |
| CVE-2025-15501 | A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the… | In your normal cycle | 9.8 critical | 6.9% | 2026-01-09 |
| CVE-2016-1761 | libxml2 in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of se… | In your normal cycle | 9.8 critical | 6.9% | 2016-03-24 |
| CVE-2018-13818 | Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is no… | In your normal cycle | 9.8 critical | 6.9% | 2018-07-10 |
| CVE-2020-24650 | A legend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior… | In your normal cycle | 9.8 critical | 6.9% | 2020-10-19 |
| CVE-2020-7142 | A eventinfo_content expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) versio… | In your normal cycle | 9.8 critical | 6.9% | 2020-10-19 |
| CVE-2020-7143 | A faultdevparasset expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version… | In your normal cycle | 9.8 critical | 6.9% | 2020-10-19 |
| CVE-2020-7144 | A comparefilesresult expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) versi… | In your normal cycle | 9.8 critical | 6.9% | 2020-10-19 |
| CVE-2020-7146 | A devgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s… | In your normal cycle | 9.8 critical | 6.9% | 2020-10-19 |
| CVE-2020-7149 | A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) ver… | In your normal cycle | 9.8 critical | 6.9% | 2020-10-19 |
| CVE-2020-7150 | A faultstatchoosefaulttype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC)… | In your normal cycle | 9.8 critical | 6.9% | 2020-10-19 |
| CVE-2020-7154 | A ifviewselectpage expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version… | In your normal cycle | 9.8 critical | 6.9% | 2020-10-19 |
| CVE-2020-7159 | A customtemplateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) ver… | In your normal cycle | 9.8 critical | 6.9% | 2020-10-19 |
| CVE-2020-7167 | A quicktemplateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) vers… | In your normal cycle | 9.8 critical | 6.9% | 2020-10-19 |
| CVE-2020-7171 | A guidatadetail expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s)… | In your normal cycle | 9.8 critical | 6.9% | 2020-10-19 |
| CVE-2020-7172 | A templateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s… | In your normal cycle | 9.8 critical | 6.9% | 2020-10-19 |
| CVE-2020-36705 | The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image func… | In your normal cycle | 9.8 critical | 6.9% | 2023-06-07 |
| CVE-2024-3566 | A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess fun… | In your normal cycle | 9.8 critical | 6.9% | 2024-04-10 |
| CVE-2021-29921 | In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allo… | In your normal cycle | 9.8 critical | 6.9% | 2021-05-06 |
| CVE-2017-14596 | In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password. | In your normal cycle | 9.8 critical | 6.9% | 2017-09-20 |
| CVE-2017-3086 | Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary c… | In your normal cycle | 9.8 critical | 6.9% | 2017-06-20 |
| CVE-2015-8386 | PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a deni… | In your normal cycle | 9.8 critical | 6.9% | 2015-12-02 |
| CVE-2018-12113 | Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response. | In your normal cycle | 9.8 critical | 6.9% | 2018-07-05 |
| CVE-2016-9051 | An exploitable out-of-bounds write vulnerability exists in the batch transaction field parsing functionality of Aerospike Database Server 3.10.0.3. A… | In your normal cycle | 9.8 critical | 6.9% | 2017-02-21 |
| CVE-2025-25948 | Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1… | In your normal cycle | 9.1 critical | 6.9% | 2025-03-03 |
| CVE-2025-45985 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0… | In your normal cycle | 9.8 critical | 6.9% | 2025-06-13 |
| CVE-2018-10592 | Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4… | In your normal cycle | 9.8 critical | 6.9% | 2018-07-31 |
| CVE-2019-3925 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.3… | In your normal cycle | 9.8 critical | 6.9% | 2019-04-30 |
| CVE-2019-3926 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14.… | In your normal cycle | 9.8 critical | 6.9% | 2019-04-30 |
| CVE-2016-1327 | Buffer overflow in the web server on Cisco DPC2203 and EPC2203 devices with firmware r1_customer_image allows remote attackers to execute arbitrary co… | In your normal cycle | 9.8 critical | 6.9% | 2016-03-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt