CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,522 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
36,734 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-15422 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.4% | 2020-07-28 |
| CVE-2020-15429 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.4% | 2020-07-28 |
| CVE-2020-15434 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.4% | 2020-07-28 |
| CVE-2020-15435 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.4% | 2020-07-28 |
| CVE-2020-15612 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.4% | 2020-07-28 |
| CVE-2022-24900 | Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulne… | In your normal cycle | 9.9 critical | 8.4% | 2022-04-29 |
| CVE-2016-9636 | Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote at… | In your normal cycle | 9.8 critical | 8.4% | 2017-01-27 |
| CVE-2018-5021 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write v… | In your normal cycle | 9.8 critical | 8.4% | 2018-07-20 |
| CVE-2018-12758 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write v… | In your normal cycle | 9.8 critical | 8.4% | 2018-07-20 |
| CVE-2018-12760 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write v… | In your normal cycle | 9.8 critical | 8.4% | 2018-07-20 |
| CVE-2018-12787 | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write v… | In your normal cycle | 9.8 critical | 8.4% | 2018-07-20 |
| CVE-2020-9664 | Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitr… | In your normal cycle | 9.8 critical | 8.4% | 2020-07-22 |
| CVE-2016-5769 | Multiple integer overflows in mcrypt.c in the mcrypt extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allow remote attackers… | In your normal cycle | 9.8 critical | 8.4% | 2016-08-07 |
| CVE-2019-25441 | thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting mali… | In your normal cycle | 9.8 critical | 8.4% | 2026-02-20 |
| CVE-2019-14809 | net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. Thi… | In your normal cycle | 9.8 critical | 8.4% | 2019-08-13 |
| CVE-2016-10190 | Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote… | In your normal cycle | 9.8 critical | 8.4% | 2017-02-09 |
| CVE-2017-15095 | A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perfor… | In your normal cycle | 9.8 critical | 8.4% | 2018-02-06 |
| CVE-2018-8787 | FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and res… | In your normal cycle | 9.8 critical | 8.4% | 2018-11-29 |
| CVE-2018-4877 | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Prim… | In your normal cycle | 9.8 critical | 8.3% | 2018-02-06 |
| CVE-2022-25322 | ZEROF Web Server 2.0 allows /HandleEvent SQL Injection. | In your normal cycle | 9.8 critical | 8.3% | 2022-02-18 |
| CVE-2020-15623 | This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is… | In your normal cycle | 9.8 critical | 8.3% | 2020-07-28 |
| CVE-2020-27619 | In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP. | In your normal cycle | 9.8 critical | 8.3% | 2020-10-22 |
| CVE-2022-0769 | The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an S… | In your normal cycle | 9.8 critical | 8.3% | 2022-04-25 |
| CVE-2018-21234 | Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set. | In your normal cycle | 9.8 critical | 8.3% | 2020-05-21 |
| CVE-2020-15611 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.3% | 2020-07-28 |
| CVE-2022-40942 | Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time. | In your normal cycle | 9.8 critical | 8.3% | 2022-09-28 |
| CVE-2017-15088 | plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows rem… | In your normal cycle | 9.8 critical | 8.3% | 2017-11-23 |
| CVE-2017-3124 | Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable me… | In your normal cycle | 9.8 critical | 8.3% | 2017-08-11 |
| CVE-2018-12823 | Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution. | In your normal cycle | 9.8 critical | 8.3% | 2018-10-17 |
| CVE-2019-7990 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitr… | In your normal cycle | 9.8 critical | 8.3% | 2019-08-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt