CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,032 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,778 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-3990 | The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery… | In your normal cycle | 9.8 critical | 6.6% | 2018-03-20 |
| CVE-2020-12651 | SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow because a banner can trigger a… | In your normal cycle | 9.8 critical | 6.6% | 2020-05-15 |
| CVE-2016-4436 | Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up. | In your normal cycle | 9.8 critical | 6.6% | 2016-10-03 |
| CVE-2024-20454 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series… | In your normal cycle | 9.8 critical | 6.6% | 2024-08-07 |
| CVE-2022-27985 | CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php. | In your normal cycle | 9.8 critical | 6.6% | 2022-04-26 |
| CVE-2018-1000832 | ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, d… | In your normal cycle | 9.8 critical | 6.6% | 2018-12-20 |
| CVE-2018-6289 | Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1. | In your normal cycle | 9.8 critical | 6.6% | 2018-02-06 |
| CVE-2019-8255 | Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. | In your normal cycle | 9.8 critical | 6.6% | 2019-12-19 |
| CVE-2025-61260 | A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) confi… | In your normal cycle | 9.8 critical | 6.6% | 2026-04-14 |
| CVE-2019-7764 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earli… | In your normal cycle | 9.8 critical | 6.6% | 2019-05-22 |
| CVE-2019-7766 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015… | In your normal cycle | 9.8 critical | 6.6% | 2019-05-22 |
| CVE-2019-7784 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015… | In your normal cycle | 9.8 critical | 6.6% | 2019-05-22 |
| CVE-2019-7788 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015… | In your normal cycle | 9.8 critical | 6.6% | 2019-05-22 |
| CVE-2019-7806 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015… | In your normal cycle | 9.8 critical | 6.6% | 2019-05-22 |
| CVE-2021-42872 | TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code. | In your normal cycle | 9.8 critical | 6.6% | 2022-06-02 |
| CVE-2021-46315 | Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW… | In your normal cycle | 9.8 critical | 6.6% | 2022-02-17 |
| CVE-2021-46319 | Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicious users ca… | In your normal cycle | 9.8 critical | 6.6% | 2022-02-17 |
| CVE-2012-4406 | OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcac… | In your normal cycle | 9.8 critical | 6.6% | 2012-10-22 |
| CVE-2017-4984 | In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may be able to… | In your normal cycle | 9.8 critical | 6.6% | 2017-06-19 |
| CVE-2016-1043 | Integer overflow in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader… | In your normal cycle | 9.8 critical | 6.6% | 2016-05-11 |
| CVE-2025-34267 | Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node V… | In your normal cycle | 9.9 critical | 6.6% | 2025-10-14 |
| CVE-2021-37579 | The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.… | In your normal cycle | 9.8 critical | 6.6% | 2021-09-09 |
| CVE-2020-29311 | Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being trigge… | In your normal cycle | 9.8 critical | 6.6% | 2020-12-10 |
| CVE-2025-14700 | An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote… | In your normal cycle | 9.9 critical | 6.6% | 2025-12-17 |
| CVE-2016-10192 | Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attacke… | In your normal cycle | 9.8 critical | 6.6% | 2017-02-09 |
| CVE-2020-25074 | The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload a… | In your normal cycle | 9.8 critical | 6.6% | 2020-11-10 |
| CVE-2017-9224 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds re… | In your normal cycle | 9.8 critical | 6.5% | 2017-05-24 |
| CVE-2021-37291 | An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php. | In your normal cycle | 9.8 critical | 6.5% | 2022-04-11 |
| CVE-2020-10885 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 router… | In your normal cycle | 9.8 critical | 6.5% | 2020-03-25 |
| CVE-2022-36972 | This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists… | In your normal cycle | 9.8 critical | 6.5% | 2023-03-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt