CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,674 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,840 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-3197 | GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BW… | In your normal cycle | 9.8 critical | 5.6% | 2018-07-09 |
| CVE-2022-3254 | The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statemen… | In your normal cycle | 9.8 critical | 5.6% | 2022-10-31 |
| CVE-2016-6980 | Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspecified vectors, a different vu… | In your normal cycle | 9.8 critical | 5.6% | 2016-09-26 |
| CVE-2022-20706 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | In your normal cycle | 10.0 critical | 5.6% | 2022-02-10 |
| CVE-2016-8584 | Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication… | In your normal cycle | 9.8 critical | 5.6% | 2017-04-28 |
| CVE-2025-9605 | A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControlInfo of the file /goform/GetPa… | In your normal cycle | 9.8 critical | 5.6% | 2025-08-29 |
| CVE-2014-9911 | Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1… | In your normal cycle | 9.8 critical | 5.6% | 2017-01-04 |
| CVE-2020-22724 | A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0… | In your normal cycle | 9.8 critical | 5.6% | 2021-10-14 |
| CVE-2016-4251 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5.6% | 2016-07-13 |
| CVE-2017-1000469 | Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as ro… | In your normal cycle | 9.8 critical | 5.6% | 2018-01-03 |
| CVE-2019-19897 | In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Service… | In your normal cycle | 9.8 critical | 5.6% | 2020-01-23 |
| CVE-2018-6641 | An Arbitrary Free (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can overwrite a structure, leading to a… | In your normal cycle | 9.8 critical | 5.6% | 2018-02-28 |
| CVE-2023-29827 | ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configu… | In your normal cycle | 9.8 critical | 5.6% | 2023-05-04 |
| CVE-2020-3765 | Adobe After Effects versions 16.1.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execut… | In your normal cycle | 9.8 critical | 5.6% | 2020-02-20 |
| CVE-2025-25038 | An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sa… | In your normal cycle | 9.8 critical | 5.6% | 2025-06-20 |
| CVE-2017-11291 | An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability exists that could be abused to… | In your normal cycle | 10.0 critical | 5.5% | 2017-12-09 |
| CVE-2020-15903 | An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included fi… | In your normal cycle | 9.8 critical | 5.5% | 2020-09-09 |
| CVE-2021-24139 | Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/… | In your normal cycle | 9.8 critical | 5.5% | 2021-03-18 |
| CVE-2024-41319 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function. | In your normal cycle | 9.8 critical | 5.5% | 2024-07-23 |
| CVE-2020-14993 | A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code… | In your normal cycle | 9.8 critical | 5.5% | 2020-06-23 |
| CVE-2018-19989 | In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.… | In your normal cycle | 9.8 critical | 5.5% | 2019-05-13 |
| CVE-2016-8512 | A Remote Code Execution vulnerability in all versions of HPE LoadRunner and Performance Center was found. | In your normal cycle | 9.8 critical | 5.5% | 2018-02-15 |
| CVE-2013-2060 | The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a requ… | In your normal cycle | 9.8 critical | 5.5% | 2020-01-28 |
| CVE-2019-12377 | A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows… | In your normal cycle | 9.8 critical | 5.5% | 2019-06-03 |
| CVE-2020-15180 | A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be ex… | In your normal cycle | 9.0 critical | 5.5% | 2021-05-27 |
| CVE-2016-6140 | SAP TREX 7.10 Revision 63 allows remote attackers to write to arbitrary files via vectors related to RFC-Gateway, aka SAP Security Note 2203591. | In your normal cycle | 9.8 critical | 5.5% | 2016-08-05 |
| CVE-2016-1000217 | Zotpress plugin for WordPress SQLi in zp_get_account() | In your normal cycle | 9.8 critical | 5.5% | 2016-10-06 |
| CVE-2016-7978 | Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .se… | In your normal cycle | 9.8 critical | 5.5% | 2017-05-23 |
| CVE-2023-3595 | Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious us… | In your normal cycle | 9.8 critical | 5.5% | 2023-07-12 |
| CVE-2021-44514 | OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories. | In your normal cycle | 9.8 critical | 5.5% | 2021-12-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt