CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,546 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,735 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-7993 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitr… | In your normal cycle | 9.8 critical | 8.3% | 2019-08-26 |
| CVE-2014-0073 | The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App… | In your normal cycle | 9.8 critical | 8.3% | 2017-10-30 |
| CVE-2019-8271 | UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer handler, which can potentially result code exe… | In your normal cycle | 9.8 critical | 8.3% | 2019-03-08 |
| CVE-2019-8273 | UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result… | In your normal cycle | 9.8 critical | 8.3% | 2019-03-08 |
| CVE-2019-8274 | UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer offer handler, which can potentially in result… | In your normal cycle | 9.8 critical | 8.3% | 2019-03-08 |
| CVE-2022-31678 | VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user t… | In your normal cycle | 9.1 critical | 8.3% | 2022-10-28 |
| CVE-2017-8768 | Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS com… | In your normal cycle | 9.8 critical | 8.3% | 2017-05-04 |
| CVE-2019-11540 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.… | In your normal cycle | 9.8 critical | 8.3% | 2019-04-26 |
| CVE-2019-15310 | An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could r… | In your normal cycle | 9.8 critical | 8.3% | 2020-07-01 |
| CVE-2018-10682 | An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authen… | In your normal cycle | 9.8 critical | 8.3% | 2018-05-09 |
| CVE-2019-8073 | ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Succ… | In your normal cycle | 9.8 critical | 8.3% | 2019-09-27 |
| CVE-2020-17510 | Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. | In your normal cycle | 9.8 critical | 8.2% | 2020-11-05 |
| CVE-2024-39367 | An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A special… | In your normal cycle | 9.1 critical | 8.2% | 2025-01-14 |
| CVE-2021-3148 | An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command… | In your normal cycle | 9.8 critical | 8.2% | 2021-02-27 |
| CVE-2021-37160 | A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before N… | In your normal cycle | 9.8 critical | 8.2% | 2021-08-02 |
| CVE-2016-6795 | In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for… | In your normal cycle | 9.8 critical | 8.2% | 2017-09-20 |
| CVE-2015-0780 | SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remot… | In your normal cycle | 9.8 critical | 8.2% | 2017-08-09 |
| CVE-2021-3199 | Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence i… | In your normal cycle | 9.8 critical | 8.2% | 2021-01-26 |
| CVE-2018-20180 | rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process… | In your normal cycle | 9.8 critical | 8.2% | 2019-03-15 |
| CVE-2018-20181 | rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process(… | In your normal cycle | 9.8 critical | 8.2% | 2019-03-15 |
| CVE-2018-20182 | rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results… | In your normal cycle | 9.8 critical | 8.2% | 2019-03-15 |
| CVE-2019-1226 | A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne… | In your normal cycle | 9.8 critical | 8.2% | 2019-08-14 |
| CVE-2023-31986 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN functi… | In your normal cycle | 9.8 critical | 8.2% | 2023-05-15 |
| CVE-2017-3207 | The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class instances from java.io.Externaliza… | In your normal cycle | 9.8 critical | 8.2% | 2018-06-11 |
| CVE-2017-3202 | The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes v… | In your normal cycle | 9.8 critical | 8.2% | 2018-06-11 |
| CVE-2015-4601 | PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected da… | In your normal cycle | 9.8 critical | 8.2% | 2016-05-16 |
| CVE-2024-39759 | Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially cr… | In your normal cycle | 10.0 critical | 8.2% | 2025-01-14 |
| CVE-2024-39761 | Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially cr… | In your normal cycle | 10.0 critical | 8.2% | 2025-01-14 |
| CVE-2021-27274 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.… | In your normal cycle | 9.8 critical | 8.2% | 2021-03-29 |
| CVE-2019-6808 | A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which… | In your normal cycle | 9.8 critical | 8.2% | 2019-05-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt