CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,522 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,734 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-8840 | A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and p… | In your normal cycle | 9.8 critical | 8.6% | 2018-04-18 |
| CVE-2017-3108 | Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability. | In your normal cycle | 9.8 critical | 8.6% | 2017-08-11 |
| CVE-2021-39510 | An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /goform… | In your normal cycle | 9.8 critical | 8.6% | 2021-08-24 |
| CVE-2018-20020 | LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that… | In your normal cycle | 9.8 critical | 8.6% | 2018-12-19 |
| CVE-2019-13917 | Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items… | In your normal cycle | 9.8 critical | 8.6% | 2019-07-25 |
| CVE-2026-0907 | Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page.… | In your normal cycle | 9.8 critical | 8.6% | 2026-01-20 |
| CVE-2017-10989 | The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a cra… | In your normal cycle | 9.8 critical | 8.6% | 2017-07-07 |
| CVE-2017-1000471 | EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of s… | In your normal cycle | 9.8 critical | 8.6% | 2018-01-03 |
| CVE-2019-1010155 | D-Link DSL-2750U 1.11 is affected by: Authentication Bypass. The impact is: denial of service and information leakage. The component is: login. NOTE:… | In your normal cycle | 9.1 critical | 8.6% | 2019-07-23 |
| CVE-2017-16924 | Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML f… | In your normal cycle | 9.8 critical | 8.6% | 2018-02-19 |
| CVE-2018-12791 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnera… | In your normal cycle | 9.8 critical | 8.6% | 2018-07-20 |
| CVE-2018-12792 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnera… | In your normal cycle | 9.8 critical | 8.6% | 2018-07-20 |
| CVE-2018-5009 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnera… | In your normal cycle | 9.8 critical | 8.6% | 2018-07-20 |
| CVE-2018-5011 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnera… | In your normal cycle | 9.8 critical | 8.6% | 2018-07-20 |
| CVE-2022-23121 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit… | In your normal cycle | 9.8 critical | 8.6% | 2023-03-28 |
| CVE-2018-0304 | A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker… | In your normal cycle | 9.8 critical | 8.6% | 2018-06-20 |
| CVE-2017-4947 | VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Success… | In your normal cycle | 9.8 critical | 8.6% | 2018-01-29 |
| CVE-2019-15823 | The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass. | In your normal cycle | 9.8 critical | 8.6% | 2019-08-30 |
| CVE-2020-10564 | An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a… | In your normal cycle | 9.8 critical | 8.6% | 2020-03-13 |
| CVE-2016-5180 | Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-… | In your normal cycle | 9.8 critical | 8.6% | 2016-10-03 |
| CVE-2020-22209 | SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php. | In your normal cycle | 9.8 critical | 8.6% | 2021-06-16 |
| CVE-2020-22210 | SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php. | In your normal cycle | 9.8 critical | 8.6% | 2021-06-16 |
| CVE-2018-11717 | An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtai… | In your normal cycle | 9.8 critical | 8.6% | 2018-07-16 |
| CVE-2018-16716 | A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arb… | In your normal cycle | 9.1 critical | 8.6% | 2019-05-02 |
| CVE-2016-4360 | web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01… | In your normal cycle | 9.1 critical | 8.6% | 2016-06-08 |
| CVE-2020-13126 | An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-1312… | In your normal cycle | 9.9 critical | 8.6% | 2020-05-17 |
| CVE-2020-9006 | The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via… | In your normal cycle | 9.8 critical | 8.6% | 2020-02-17 |
| CVE-2016-4658 | xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does… | In your normal cycle | 9.8 critical | 8.6% | 2016-09-25 |
| CVE-2019-3910 | Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote use… | In your normal cycle | 9.1 critical | 8.6% | 2019-01-18 |
| CVE-2018-12812 | Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions have a Type Confusion vulnera… | In your normal cycle | 9.8 critical | 8.6% | 2018-07-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt