CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,696 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,955 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-1130 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 3.7% | 2016-05-11 |
| CVE-2021-21465 | The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker c… | In your normal cycle | 9.9 critical | 3.7% | 2021-01-12 |
| CVE-2021-45998 | D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vu… | In your normal cycle | 9.8 critical | 3.7% | 2022-02-04 |
| CVE-2021-46226 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability… | In your normal cycle | 9.8 critical | 3.7% | 2022-02-04 |
| CVE-2021-46228 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerabilit… | In your normal cycle | 9.8 critical | 3.7% | 2022-02-04 |
| CVE-2021-46455 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStationSettings. This vulnerabi… | In your normal cycle | 9.8 critical | 3.7% | 2022-02-04 |
| CVE-2021-46456 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanACLSettings. This vulnerabi… | In your normal cycle | 9.8 critical | 3.7% | 2022-02-04 |
| CVE-2021-46457 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgSambaUserSettings. This vulnera… | In your normal cycle | 9.8 critical | 3.7% | 2022-02-04 |
| CVE-2020-23426 | zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for f… | In your normal cycle | 9.8 critical | 3.7% | 2021-04-08 |
| CVE-2025-13773 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5… | In your normal cycle | 9.8 critical | 3.7% | 2025-12-24 |
| CVE-2026-26791 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server functi… | In your normal cycle | 9.8 critical | 3.7% | 2026-03-12 |
| CVE-2026-26793 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attacke… | In your normal cycle | 9.8 critical | 3.7% | 2026-03-12 |
| CVE-2026-26795 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. Thi… | In your normal cycle | 9.8 critical | 3.7% | 2026-03-12 |
| CVE-2017-1000047 | rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbitrary code execution | In your normal cycle | 9.8 critical | 3.7% | 2017-07-17 |
| CVE-2021-33962 | China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device compone… | In your normal cycle | 9.8 critical | 3.7% | 2022-01-14 |
| CVE-2019-18224 | idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string. | In your normal cycle | 9.8 critical | 3.7% | 2019-10-21 |
| CVE-2019-8206 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | In your normal cycle | 9.8 critical | 3.7% | 2019-10-17 |
| CVE-2021-40525 | Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writi… | In your normal cycle | 9.1 critical | 3.7% | 2022-01-04 |
| CVE-2017-5398 | Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort t… | In your normal cycle | 9.8 critical | 3.7% | 2018-06-11 |
| CVE-2021-21804 | A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially cra… | In your normal cycle | 9.8 critical | 3.7% | 2021-07-16 |
| CVE-2021-39379 | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL… | In your normal cycle | 9.8 critical | 3.7% | 2021-09-01 |
| CVE-2021-25914 | Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remot… | In your normal cycle | 9.8 critical | 3.7% | 2021-03-01 |
| CVE-2016-20010 | EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable… | In your normal cycle | 10.0 critical | 3.7% | 2021-05-05 |
| CVE-2019-13962 | lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not pro… | In your normal cycle | 9.8 critical | 3.7% | 2019-07-18 |
| CVE-2016-10328 | FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.… | In your normal cycle | 9.8 critical | 3.7% | 2017-04-14 |
| CVE-2020-13931 | If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker con… | In your normal cycle | 9.8 critical | 3.7% | 2020-12-18 |
| CVE-2020-15489 | An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI script… | In your normal cycle | 9.8 critical | 3.7% | 2020-07-01 |
| CVE-2018-11241 | An issue was discovered on SoftCase T-Router build 20112017 devices. A remote attacker can read and write to arbitrary files on the system as root, as… | In your normal cycle | 9.8 critical | 3.7% | 2018-09-21 |
| CVE-2018-15723 | The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated rem… | In your normal cycle | 9.8 critical | 3.7% | 2018-12-20 |
| CVE-2018-14353 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow. | In your normal cycle | 9.8 critical | 3.7% | 2018-07-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt