CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,556 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,833 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-7886 | Adobe InDesign version 11.4.1 and earlier, Adobe InDesign Server 11.0.0 and earlier have an exploitable memory corruption vulnerability. Successful ex… | In your normal cycle | 9.8 critical | 6.3% | 2016-12-15 |
| CVE-2020-3799 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and… | In your normal cycle | 9.8 critical | 6.3% | 2020-03-25 |
| CVE-2020-3807 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and… | In your normal cycle | 9.8 critical | 6.3% | 2020-03-25 |
| CVE-2016-1062 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 6.3% | 2016-05-11 |
| CVE-2016-1117 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 6.3% | 2016-05-11 |
| CVE-2024-22611 | OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controlle… | In your normal cycle | 9.8 critical | 6.3% | 2025-04-03 |
| CVE-2015-5589 | The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 does not validate a fi… | In your normal cycle | 9.8 critical | 6.3% | 2016-05-16 |
| CVE-2024-29224 | An OS command injection vulnerability exists in the NAT parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command exec… | In your normal cycle | 9.8 critical | 6.3% | 2024-11-21 |
| CVE-2018-1000804 | contiki-ng version 4 contains a Buffer Overflow vulnerability in AQL (Antelope Query Language) database engine that can result in Attacker can perform… | In your normal cycle | 9.8 critical | 6.3% | 2018-10-08 |
| CVE-2016-4522 | SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to execute arbitrary SQL commands v… | In your normal cycle | 9.8 critical | 6.3% | 2016-07-28 |
| CVE-2016-1041 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 10.0 critical | 6.3% | 2016-05-11 |
| CVE-2016-1039 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 6.3% | 2016-05-11 |
| CVE-2016-1042 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 6.3% | 2016-05-11 |
| CVE-2018-1000116 | NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution. | In your normal cycle | 9.8 critical | 6.3% | 2018-03-07 |
| CVE-2017-14728 | An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of… | In your normal cycle | 9.8 critical | 6.3% | 2019-06-03 |
| CVE-2017-1000116 | Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks. | In your normal cycle | 9.8 critical | 6.3% | 2017-10-05 |
| CVE-2017-3159 | Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to securi… | In your normal cycle | 9.8 critical | 6.3% | 2017-03-07 |
| CVE-2022-28615 | Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extreme… | In your normal cycle | 9.1 critical | 6.3% | 2022-06-09 |
| CVE-2016-2173 | org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code. | In your normal cycle | 9.8 critical | 6.3% | 2017-04-21 |
| CVE-2019-3859 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote atta… | In your normal cycle | 9.1 critical | 6.3% | 2019-03-21 |
| CVE-2019-1010238 | Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The compo… | In your normal cycle | 9.8 critical | 6.3% | 2019-07-19 |
| CVE-2019-11196 | An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote atta… | In your normal cycle | 9.8 critical | 6.3% | 2019-04-12 |
| CVE-2016-6296 | Integer signedness error in the simplestring_addn function in simplestring.c in xmlrpc-epi through 0.54.2, as used in PHP before 5.5.38, 5.6.x before… | In your normal cycle | 9.8 critical | 6.3% | 2016-07-25 |
| CVE-2016-4120 | Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to… | In your normal cycle | 9.8 critical | 6.3% | 2016-06-16 |
| CVE-2016-4160 | Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to… | In your normal cycle | 9.8 critical | 6.3% | 2016-06-16 |
| CVE-2016-4161 | Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to… | In your normal cycle | 9.8 critical | 6.3% | 2016-06-16 |
| CVE-2016-4162 | Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to… | In your normal cycle | 9.8 critical | 6.3% | 2016-06-16 |
| CVE-2016-4163 | Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to… | In your normal cycle | 9.8 critical | 6.3% | 2016-06-16 |
| CVE-2017-9227 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds re… | In your normal cycle | 9.8 critical | 6.3% | 2017-05-24 |
| CVE-2024-6779 | Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a cra… | In your normal cycle | 9.6 critical | 6.3% | 2024-07-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt