CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,893 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,880 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-21646 | Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When… | In your normal cycle | 9.8 critical | 5.1% | 2024-01-09 |
| CVE-2022-30600 | A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed. | In your normal cycle | 9.8 critical | 5.1% | 2022-05-18 |
| CVE-2019-19810 | Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attack… | In your normal cycle | 10.0 critical | 5.1% | 2021-10-28 |
| CVE-2016-7568 | Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allo… | In your normal cycle | 9.8 critical | 5.1% | 2016-09-28 |
| CVE-2022-25371 | Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in… | In your normal cycle | 9.8 critical | 5.1% | 2022-09-02 |
| CVE-2019-20427 | In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic, and possibly remote code execution, due to the lack of val… | In your normal cycle | 9.8 critical | 5.1% | 2020-01-27 |
| CVE-2014-5334 | FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login. | In your normal cycle | 9.8 critical | 5.1% | 2018-01-08 |
| CVE-2021-39509 | An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/fo… | In your normal cycle | 9.8 critical | 5.1% | 2021-08-24 |
| CVE-2017-14952 | Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary cod… | In your normal cycle | 9.8 critical | 5.1% | 2017-10-16 |
| CVE-2018-10996 | The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of service (buff… | In your normal cycle | 9.8 critical | 5.1% | 2018-05-12 |
| CVE-2010-20103 | A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor imp… | In your normal cycle | 9.8 critical | 5.1% | 2025-08-20 |
| CVE-2026-14894 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 v… | In your normal cycle | 9.8 critical | 5.1% | 2026-07-10 |
| CVE-2020-15188 | SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code wh… | In your normal cycle | 10.0 critical | 5.1% | 2020-09-18 |
| CVE-2021-34082 | OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attack… | In your normal cycle | 9.8 critical | 5.1% | 2022-06-02 |
| CVE-2016-4212 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5.1% | 2016-07-13 |
| CVE-2016-7015 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5.1% | 2016-10-13 |
| CVE-2016-5531 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers… | In your normal cycle | 9.8 critical | 5.1% | 2016-10-25 |
| CVE-2016-5535 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows remote… | In your normal cycle | 9.8 critical | 5.1% | 2016-10-25 |
| CVE-2018-10635 | In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbitrary URScript code and execut… | In your normal cycle | 9.8 critical | 5.1% | 2018-07-11 |
| CVE-2015-8366 | Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execu… | In your normal cycle | 9.8 critical | 5.1% | 2020-01-14 |
| CVE-2022-25167 | Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LD… | In your normal cycle | 9.8 critical | 5.1% | 2022-06-14 |
| CVE-2017-9542 | D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to vali… | In your normal cycle | 9.8 critical | 5.1% | 2017-06-11 |
| CVE-2018-12714 | An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c could be called with no filter, w… | In your normal cycle | 9.8 critical | 5.1% | 2018-06-24 |
| CVE-2019-7768 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015… | In your normal cycle | 9.8 critical | 5.1% | 2019-05-22 |
| CVE-2019-7782 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015… | In your normal cycle | 9.8 critical | 5.1% | 2019-05-22 |
| CVE-2019-7992 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to… | In your normal cycle | 9.8 critical | 5.1% | 2019-08-26 |
| CVE-2020-5639 | Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitrary file in a specific director… | In your normal cycle | 9.8 critical | 5.1% | 2020-12-14 |
| CVE-2018-12829 | Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful exploitation could lead to priv… | In your normal cycle | 9.8 critical | 5.1% | 2018-08-29 |
| CVE-2022-27002 | Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host p… | In your normal cycle | 9.8 critical | 5.1% | 2022-03-15 |
| CVE-2021-44548 | An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB ne… | In your normal cycle | 9.8 critical | 5.1% | 2021-12-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt