CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,226 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,903 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-8105 | FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in… | In your normal cycle | 9.8 critical | 4.4% | 2017-04-24 |
| CVE-2020-24918 | A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to send a crafted RTSP request,… | In your normal cycle | 9.8 critical | 4.4% | 2021-04-30 |
| CVE-2020-7633 | apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument. | In your normal cycle | 9.8 critical | 4.4% | 2020-04-06 |
| CVE-2020-7635 | compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument. | In your normal cycle | 9.8 critical | 4.4% | 2020-04-06 |
| CVE-2020-7636 | adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function. | In your normal cycle | 9.8 critical | 4.4% | 2020-04-06 |
| CVE-2022-21723 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, ST… | In your normal cycle | 9.1 critical | 4.4% | 2022-01-27 |
| CVE-2022-23125 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit… | In your normal cycle | 9.8 critical | 4.4% | 2023-03-28 |
| CVE-2018-12313 | OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity"… | In your normal cycle | 9.8 critical | 4.4% | 2018-12-04 |
| CVE-2019-7958 | Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability. Successful exploitation could lead… | In your normal cycle | 9.8 critical | 4.4% | 2019-08-16 |
| CVE-2019-1365 | An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attack… | In your normal cycle | 9.9 critical | 4.4% | 2019-10-10 |
| CVE-2016-5408 | Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux… | In your normal cycle | 9.8 critical | 4.4% | 2016-08-10 |
| CVE-2017-1000501 | Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthent… | In your normal cycle | 9.8 critical | 4.4% | 2018-01-03 |
| CVE-2019-13589 | The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, w… | In your normal cycle | 9.8 critical | 4.4% | 2019-07-14 |
| CVE-2020-8584 | Element OS versions prior to 1.8P1 and 12.2 are susceptible to a vulnerability that could allow an unauthenticated remote attacker to perform arbitrar… | In your normal cycle | 9.8 critical | 4.4% | 2021-01-08 |
| CVE-2019-7131 | Adobe Acrobat and Reader versions 2019.010.20064 and earlier, 2019.010.20064 and earlier, 2017.011.30110 and earlier version, and 2015.006.30461 and e… | In your normal cycle | 9.8 critical | 4.4% | 2020-01-28 |
| CVE-2021-41269 | cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A tem… | In your normal cycle | 10.0 critical | 4.3% | 2021-11-15 |
| CVE-2019-11185 | The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patc… | In your normal cycle | 9.8 critical | 4.3% | 2019-06-03 |
| CVE-2020-35590 | LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because… | In your normal cycle | 9.8 critical | 4.3% | 2020-12-21 |
| CVE-2017-13033 | The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print(). | In your normal cycle | 9.8 critical | 4.3% | 2017-09-14 |
| CVE-2020-10225 | An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploit… | In your normal cycle | 9.8 critical | 4.3% | 2020-03-08 |
| CVE-2021-1142 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary… | In your normal cycle | 9.8 critical | 4.3% | 2021-01-20 |
| CVE-2015-1820 | REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information… | In your normal cycle | 9.8 critical | 4.3% | 2017-08-09 |
| CVE-2024-0799 | An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.… | In your normal cycle | 9.8 critical | 4.3% | 2024-03-13 |
| CVE-2022-33312 | Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted netwo… | In your normal cycle | 9.8 critical | 4.3% | 2022-06-30 |
| CVE-2022-33313 | Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted netwo… | In your normal cycle | 9.8 critical | 4.3% | 2022-06-30 |
| CVE-2022-33314 | Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted netwo… | In your normal cycle | 9.8 critical | 4.3% | 2022-06-30 |
| CVE-2022-33325 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network… | In your normal cycle | 9.8 critical | 4.3% | 2022-06-30 |
| CVE-2022-33326 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network… | In your normal cycle | 9.8 critical | 4.3% | 2022-06-30 |
| CVE-2022-33327 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network… | In your normal cycle | 9.8 critical | 4.3% | 2022-06-30 |
| CVE-2022-33328 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network… | In your normal cycle | 9.8 critical | 4.3% | 2022-06-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt