CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,553 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
36,833 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-15896 | An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is… | In your normal cycle | 9.8 critical | 6.5% | 2019-09-10 |
| CVE-2016-4464 | The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured… | In your normal cycle | 9.8 critical | 6.5% | 2016-09-21 |
| CVE-2017-9830 | Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiation) it cre… | In your normal cycle | 9.8 critical | 6.5% | 2017-06-27 |
| CVE-2021-44675 | Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which… | In your normal cycle | 9.8 critical | 6.5% | 2021-12-20 |
| CVE-2019-7268 | Linear eMerge 50P/5000P devices allow Unauthenticated File Upload. | In your normal cycle | 10.0 critical | 6.5% | 2019-07-02 |
| CVE-2018-6797 | An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes wr… | In your normal cycle | 9.8 critical | 6.5% | 2018-04-17 |
| CVE-2017-11302 | An issue was discovered in Adobe InDesign 12.1.0 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation… | In your normal cycle | 9.8 critical | 6.5% | 2017-12-09 |
| CVE-2025-14708 | A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/http_e… | In your normal cycle | 9.8 critical | 6.5% | 2025-12-15 |
| CVE-2017-1000215 | ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution | In your normal cycle | 9.8 critical | 6.5% | 2017-11-17 |
| CVE-2025-49388 | Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Privilege Escalation.This issue affects Mira… | In your normal cycle | 9.8 critical | 6.5% | 2025-08-28 |
| CVE-2018-10510 | A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute arb… | In your normal cycle | 9.8 critical | 6.5% | 2018-08-15 |
| CVE-2016-1075 | Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Ac… | In your normal cycle | 9.8 critical | 6.5% | 2016-05-11 |
| CVE-2026-53787 | Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated… | In your normal cycle | 9.8 critical | 6.5% | 2026-06-12 |
| CVE-2024-28892 | An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command exe… | In your normal cycle | 9.8 critical | 6.5% | 2024-11-21 |
| CVE-2018-11013 | Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware version 1.10B05 allows unauthentic… | In your normal cycle | 9.8 critical | 6.4% | 2018-05-13 |
| CVE-2016-2397 | The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deseria… | In your normal cycle | 9.8 critical | 6.4% | 2016-02-17 |
| CVE-2023-6319 | A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 t… | In your normal cycle | 9.1 critical | 6.4% | 2024-04-09 |
| CVE-2017-12337 | A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an un… | In your normal cycle | 9.8 critical | 6.4% | 2017-11-16 |
| CVE-2020-28902 | Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php. | In your normal cycle | 9.8 critical | 6.4% | 2021-05-24 |
| CVE-2019-7094 | Adobe Photoshop CC 19.1.7 and earlier, and 20.0.2 and earlier have a heap corruption vulnerability. Successful exploitation could lead to arbitrary co… | In your normal cycle | 9.8 critical | 6.4% | 2019-05-24 |
| CVE-2019-7969 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbit… | In your normal cycle | 9.8 critical | 6.4% | 2019-08-26 |
| CVE-2019-7970 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbit… | In your normal cycle | 9.8 critical | 6.4% | 2019-08-26 |
| CVE-2019-7971 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbit… | In your normal cycle | 9.8 critical | 6.4% | 2019-08-26 |
| CVE-2019-7972 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbit… | In your normal cycle | 9.8 critical | 6.4% | 2019-08-26 |
| CVE-2019-7973 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbit… | In your normal cycle | 9.8 critical | 6.4% | 2019-08-26 |
| CVE-2019-7974 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbit… | In your normal cycle | 9.8 critical | 6.4% | 2019-08-26 |
| CVE-2019-7975 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbit… | In your normal cycle | 9.8 critical | 6.4% | 2019-08-26 |
| CVE-2019-7997 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to… | In your normal cycle | 9.8 critical | 6.4% | 2019-08-26 |
| CVE-2019-7998 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to… | In your normal cycle | 9.8 critical | 6.4% | 2019-08-26 |
| CVE-2019-8001 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to… | In your normal cycle | 9.8 critical | 6.4% | 2019-08-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt