CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,546 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,735 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-8786 | FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() a… | In your normal cycle | 9.8 critical | 8.2% | 2018-11-29 |
| CVE-2019-18184 | Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function. | In your normal cycle | 9.8 critical | 8.2% | 2019-11-27 |
| CVE-2016-4432 | The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and conse… | In your normal cycle | 9.1 critical | 8.1% | 2016-06-01 |
| CVE-2025-7776 | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScal… | In your normal cycle | 9.8 critical | 8.1% | 2025-08-26 |
| CVE-2017-12627 | In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions… | In your normal cycle | 9.8 critical | 8.1% | 2018-03-01 |
| CVE-2023-32314 | vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and includi… | In your normal cycle | 9.8 critical | 8.1% | 2023-05-15 |
| CVE-2020-11974 | In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database. | In your normal cycle | 9.8 critical | 8.1% | 2020-12-18 |
| CVE-2019-14379 | SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transacti… | In your normal cycle | 9.8 critical | 8.1% | 2019-07-29 |
| CVE-2019-11949 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | In your normal cycle | 9.8 critical | 8.1% | 2019-06-05 |
| CVE-2019-5352 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | In your normal cycle | 9.8 critical | 8.1% | 2019-06-05 |
| CVE-2019-5358 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | In your normal cycle | 9.8 critical | 8.1% | 2019-06-05 |
| CVE-2019-5387 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | In your normal cycle | 9.8 critical | 8.1% | 2019-06-05 |
| CVE-2014-1493 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and… | In your normal cycle | 9.8 critical | 8.1% | 2014-03-19 |
| CVE-2018-11756 | In PHP Runtime for Apache OpenWhisk, a Docker action inheriting one of the Docker tags openwhisk/action-php-v7.2:1.0.0 or openwhisk/action-php-v7.1:1.… | In your normal cycle | 9.8 critical | 8.1% | 2018-07-23 |
| CVE-2013-5609 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and… | In your normal cycle | 9.8 critical | 8.1% | 2013-12-11 |
| CVE-2017-7213 | Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vec… | In your normal cycle | 10.0 critical | 8.1% | 2017-05-15 |
| CVE-2024-31848 | A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could al… | In your normal cycle | 9.8 critical | 8.1% | 2024-04-05 |
| CVE-2020-15420 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-el7-0.9.8.891. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15421 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15423 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15424 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15425 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15426 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15427 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15428 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15430 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15431 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15432 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15433 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
| CVE-2020-15606 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… | In your normal cycle | 9.8 critical | 8.1% | 2020-07-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt