CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,556 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,835 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-5021 | Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the res… | In your normal cycle | 9.8 critical | 6.3% | 2019-05-08 |
| CVE-2017-9228 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds wri… | In your normal cycle | 9.8 critical | 6.3% | 2017-05-24 |
| CVE-2016-1999 | The server in HP Release Control 9.13, 9.20, and 9.21 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, rela… | In your normal cycle | 9.8 critical | 6.3% | 2016-05-30 |
| CVE-2000-1218 | The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which c… | In your normal cycle | 9.8 critical | 6.3% | 2000-04-14 |
| CVE-2022-47002 | A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request. | In your normal cycle | 9.8 critical | 6.3% | 2023-02-01 |
| CVE-2017-1000037 | RVM automatically loads environment variables from files in $PWD resulting in command execution RVM vulnerable to command injection when automatically… | In your normal cycle | 9.8 critical | 6.2% | 2017-07-17 |
| CVE-2024-52316 | Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthC… | In your normal cycle | 9.8 critical | 6.2% | 2024-11-18 |
| CVE-2016-1928 | Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a crafte… | In your normal cycle | 9.8 critical | 6.2% | 2016-01-20 |
| CVE-2022-21849 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | In your normal cycle | 9.8 critical | 6.2% | 2022-01-11 |
| CVE-2016-1243 | Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute arbitrary code via a long pathname. | In your normal cycle | 9.8 critical | 6.2% | 2016-10-03 |
| CVE-2018-19698 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… | In your normal cycle | 9.8 critical | 6.2% | 2019-01-18 |
| CVE-2018-19700 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… | In your normal cycle | 9.8 critical | 6.2% | 2019-01-18 |
| CVE-2019-12489 | An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP r… | In your normal cycle | 9.8 critical | 6.2% | 2019-11-26 |
| CVE-2013-7455 | Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute… | In your normal cycle | 9.8 critical | 6.2% | 2016-05-07 |
| CVE-2017-1000257 | An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would… | In your normal cycle | 9.1 critical | 6.2% | 2017-10-31 |
| CVE-2019-12890 | RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationf… | In your normal cycle | 9.8 critical | 6.2% | 2019-06-19 |
| CVE-2024-43360 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability.… | In your normal cycle | 9.8 critical | 6.2% | 2024-08-12 |
| CVE-2022-4047 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action avai… | In your normal cycle | 9.8 critical | 6.2% | 2022-12-26 |
| CVE-2017-3112 | An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data… | In your normal cycle | 9.8 critical | 6.2% | 2017-12-09 |
| CVE-2017-3114 | An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data… | In your normal cycle | 9.8 critical | 6.2% | 2017-12-09 |
| CVE-2021-44734 | Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the d… | In your normal cycle | 9.8 critical | 6.2% | 2022-01-20 |
| CVE-2021-23926 | The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities i… | In your normal cycle | 9.1 critical | 6.2% | 2021-01-14 |
| CVE-2017-15702 | In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an H… | In your normal cycle | 9.8 critical | 6.2% | 2017-12-01 |
| CVE-2023-46846 | SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past… | In your normal cycle | 9.3 critical | 6.2% | 2023-11-03 |
| CVE-2017-11240 | Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an expl… | In your normal cycle | 9.8 critical | 6.2% | 2018-05-19 |
| CVE-2017-11250 | Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an expl… | In your normal cycle | 9.8 critical | 6.2% | 2018-05-19 |
| CVE-2017-11253 | Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an expl… | In your normal cycle | 9.8 critical | 6.2% | 2018-05-19 |
| CVE-2017-11306 | Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an expl… | In your normal cycle | 9.8 critical | 6.2% | 2018-05-19 |
| CVE-2017-11307 | Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an expl… | In your normal cycle | 9.8 critical | 6.2% | 2018-05-19 |
| CVE-2008-5038 | Use-after-free vulnerability in the NetWare Core Protocol (NCP) feature in Novell eDirectory 8.7.3 SP10 before 8.7.3 SP10 FTF1 and 8.8 SP2 for Windows… | In your normal cycle | 9.8 critical | 6.2% | 2008-11-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt