CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,585 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,835 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-24329 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRule… | In your normal cycle | 9.8 critical | 6.2% | 2024-01-30 |
| CVE-2015-8299 | Buffer overflow in the Group messages monitor (Falcon) in KNX ETS 4.1.5 (Build 3246) allows remote attackers to execute arbitrary code via a crafted K… | In your normal cycle | 9.8 critical | 6.2% | 2017-08-29 |
| CVE-2021-4473 | Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated… | In your normal cycle | 9.8 critical | 6.2% | 2026-04-07 |
| CVE-2026-10886 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted H… | In your normal cycle | 9.6 critical | 6.2% | 2026-06-04 |
| CVE-2020-27744 | An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privile… | In your normal cycle | 9.8 critical | 6.2% | 2020-10-29 |
| CVE-2020-29495 | DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacke… | In your normal cycle | 10.0 critical | 6.2% | 2021-01-14 |
| CVE-2016-0933 | Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 6.2% | 2016-01-14 |
| CVE-2018-7218 | The AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.2… | In your normal cycle | 9.8 critical | 6.2% | 2018-05-17 |
| CVE-2019-7105 | Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution. | In your normal cycle | 9.8 critical | 6.2% | 2019-05-23 |
| CVE-2019-7106 | Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution. | In your normal cycle | 9.8 critical | 6.2% | 2019-05-23 |
| CVE-2016-1289 | The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary… | In your normal cycle | 9.8 critical | 6.2% | 2016-07-02 |
| CVE-2016-2337 | Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can caus… | In your normal cycle | 9.8 critical | 6.2% | 2017-01-06 |
| CVE-2017-3088 | Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF runtime engine. Successful exploitati… | In your normal cycle | 10.0 critical | 6.2% | 2017-06-20 |
| CVE-2017-3089 | Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF imaging model. Successful exploitatio… | In your normal cycle | 9.8 critical | 6.2% | 2017-06-20 |
| CVE-2017-3093 | Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the bitmap representation module. Successful… | In your normal cycle | 9.8 critical | 6.2% | 2017-06-20 |
| CVE-2017-3094 | Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF processing engine. Successful exploit… | In your normal cycle | 9.8 critical | 6.2% | 2017-06-20 |
| CVE-2017-3095 | Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF parsing engine. Successful exploitati… | In your normal cycle | 9.8 critical | 6.2% | 2017-06-20 |
| CVE-2017-3096 | Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the character code mapping module. Successful… | In your normal cycle | 9.8 critical | 6.2% | 2017-06-20 |
| CVE-2016-7001 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 6.2% | 2016-10-13 |
| CVE-2016-7002 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 6.2% | 2016-10-13 |
| CVE-2016-7003 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 6.2% | 2016-10-13 |
| CVE-2016-7004 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 6.2% | 2016-10-13 |
| CVE-2018-14354 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquot… | In your normal cycle | 9.8 critical | 6.2% | 2018-07-17 |
| CVE-2023-39796 | SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_REC… | In your normal cycle | 9.8 critical | 6.1% | 2023-11-10 |
| CVE-2019-14537 | YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass. | In your normal cycle | 9.8 critical | 6.1% | 2019-08-07 |
| CVE-2026-38360 | Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_… | In your normal cycle | 9.8 critical | 6.1% | 2026-05-08 |
| CVE-2026-15748 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_uplo… | In your normal cycle | 9.8 critical | 6.1% | 2026-08-18 |
| CVE-2019-18780 | An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute… | In your normal cycle | 9.8 critical | 6.1% | 2019-11-05 |
| CVE-2020-1946 | In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. W… | In your normal cycle | 9.8 critical | 6.1% | 2021-03-25 |
| CVE-2018-3779 | active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An att… | In your normal cycle | 9.8 critical | 6.1% | 2018-08-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt