CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,585 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,835 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-8779 | Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause… | In your normal cycle | 9.8 critical | 6.2% | 2016-04-19 |
| CVE-2016-4000 | Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object. | In your normal cycle | 9.8 critical | 6.2% | 2017-07-06 |
| CVE-2020-27159 | Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western D… | In your normal cycle | 9.8 critical | 6.2% | 2020-10-27 |
| CVE-2018-8097 | io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter. | In your normal cycle | 9.8 critical | 6.2% | 2018-03-14 |
| CVE-2019-7832 | Adobe Acrobat and Reader versions , 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 20… | In your normal cycle | 9.8 critical | 6.2% | 2019-05-22 |
| CVE-2021-40422 | An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted n… | In your normal cycle | 10.0 critical | 6.2% | 2022-04-14 |
| CVE-2017-11543 | tcpdump 4.9.0 has a buffer overflow in the sliplink_print function in print-sl.c. | In your normal cycle | 9.8 critical | 6.2% | 2017-07-23 |
| CVE-2017-5484 | The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print(). | In your normal cycle | 9.8 critical | 6.2% | 2017-01-28 |
| CVE-2015-5243 | phpWhois allows remote attackers to execute arbitrary code via a crafted whois record. | In your normal cycle | 9.8 critical | 6.2% | 2018-08-20 |
| CVE-2015-8835 | The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not properly retrie… | In your normal cycle | 9.8 critical | 6.2% | 2016-05-16 |
| CVE-2024-39784 | Multiple command execution vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP… | In your normal cycle | 9.1 critical | 6.2% | 2025-01-14 |
| CVE-2024-39785 | Multiple command execution vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP… | In your normal cycle | 9.1 critical | 6.2% | 2025-01-14 |
| CVE-2020-20982 | Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the ba… | In your normal cycle | 9.6 critical | 6.2% | 2021-11-03 |
| CVE-2021-21121 | Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a craf… | In your normal cycle | 9.6 critical | 6.2% | 2021-02-09 |
| CVE-2008-7319 | The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters… | In your normal cycle | 9.8 critical | 6.2% | 2017-11-07 |
| CVE-2014-4981 | LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization of the web GUI parameters. | In your normal cycle | 9.8 critical | 6.2% | 2020-02-17 |
| CVE-2021-43033 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary re… | In your normal cycle | 9.8 critical | 6.2% | 2021-12-06 |
| CVE-2020-1036 | A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user o… | In your normal cycle | 9.0 critical | 6.2% | 2020-07-14 |
| CVE-2017-2096 | smalruby-editor v0.4.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. | In your normal cycle | 9.8 critical | 6.2% | 2017-04-28 |
| CVE-2019-9117 | An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote at… | In your normal cycle | 9.8 critical | 6.2% | 2019-03-07 |
| CVE-2019-9118 | An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote at… | In your normal cycle | 9.8 critical | 6.2% | 2019-03-07 |
| CVE-2019-9119 | An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote at… | In your normal cycle | 9.8 critical | 6.2% | 2019-03-07 |
| CVE-2019-9120 | An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote at… | In your normal cycle | 9.8 critical | 6.2% | 2019-03-07 |
| CVE-2019-7096 | Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an use after free vulnerability. Successfu… | In your normal cycle | 9.8 critical | 6.2% | 2019-05-23 |
| CVE-2017-5337 | Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unsp… | In your normal cycle | 9.8 critical | 6.2% | 2017-03-24 |
| CVE-2017-7280 | An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sent… | In your normal cycle | 9.8 critical | 6.2% | 2017-04-12 |
| CVE-2020-29564 | The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul Docker container deployed by a… | In your normal cycle | 9.8 critical | 6.2% | 2020-12-08 |
| CVE-2020-6143 | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable which is set at line 122 in inst… | In your normal cycle | 9.8 critical | 6.2% | 2020-09-01 |
| CVE-2020-6144 | A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable which is set at line 121 in inst… | In your normal cycle | 9.8 critical | 6.2% | 2020-09-01 |
| CVE-2024-24328 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules… | In your normal cycle | 9.8 critical | 6.2% | 2024-01-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt