CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,593 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,835 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-5690 | The ReadDCMImage function in DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact via ve… | In your normal cycle | 9.8 critical | 6.1% | 2016-12-13 |
| CVE-2016-5691 | The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validatio… | In your normal cycle | 9.8 critical | 6.1% | 2016-12-13 |
| CVE-2018-9249 | FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an… | In your normal cycle | 9.8 critical | 6.1% | 2018-04-04 |
| CVE-2015-8459 | Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0… | In your normal cycle | 10.0 critical | 6.1% | 2015-12-28 |
| CVE-2009-5153 | In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allowed remote… | In your normal cycle | 9.8 critical | 6.1% | 2018-11-21 |
| CVE-2018-7225 | An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to ac… | In your normal cycle | 9.8 critical | 6.1% | 2018-02-19 |
| CVE-2018-10870 | redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file… | In your normal cycle | 9.8 critical | 6.1% | 2018-07-19 |
| CVE-2016-1007 | Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 6.1% | 2016-03-09 |
| CVE-2016-1009 | Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 6.1% | 2016-03-09 |
| CVE-2016-4460 | Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication. | In your normal cycle | 9.8 critical | 6.1% | 2017-08-22 |
| CVE-2020-29284 | The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows… | In your normal cycle | 9.8 critical | 6.1% | 2020-12-02 |
| CVE-2019-6550 | Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple stack-based buffer overflow vulnerabilities, caused by a lack of proper validation of th… | In your normal cycle | 9.8 critical | 6.1% | 2019-04-05 |
| CVE-2022-38637 | Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login… | In your normal cycle | 9.8 critical | 6.1% | 2022-09-13 |
| CVE-2014-1514 | vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not valid… | In your normal cycle | 9.8 critical | 6.1% | 2014-03-19 |
| CVE-2017-3186 | ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all devices. A r… | In your normal cycle | 9.8 critical | 6.1% | 2017-12-16 |
| CVE-2016-1962 | Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 all… | In your normal cycle | 9.8 critical | 6.1% | 2016-03-13 |
| CVE-2020-25765 | Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior… | In your normal cycle | 9.8 critical | 6.1% | 2020-10-27 |
| CVE-2015-8383 | PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possi… | In your normal cycle | 9.8 critical | 6.1% | 2015-12-02 |
| CVE-2017-11215 | An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in… | In your normal cycle | 9.8 critical | 6.1% | 2017-12-09 |
| CVE-2017-11225 | An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in… | In your normal cycle | 9.8 critical | 6.1% | 2017-12-09 |
| CVE-2024-31849 | A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow… | In your normal cycle | 9.8 critical | 6.1% | 2024-04-05 |
| CVE-2017-8390 | The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to exec… | In your normal cycle | 9.8 critical | 6.1% | 2017-08-02 |
| CVE-2024-35387 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth. | In your normal cycle | 9.8 critical | 6.1% | 2024-05-24 |
| CVE-2025-15500 | A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /… | In your normal cycle | 9.8 critical | 6.1% | 2026-01-09 |
| CVE-2017-14474 | In the MMM::Agent::Helpers::_execute function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1, a specially crafted MMM protocol messa… | In your normal cycle | 9.8 critical | 6.1% | 2018-05-09 |
| CVE-2017-14475 | In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted… | In your normal cycle | 9.8 critical | 6.1% | 2018-05-09 |
| CVE-2016-4538 | The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without… | In your normal cycle | 9.8 critical | 6.1% | 2016-05-22 |
| CVE-2016-4539 | The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a… | In your normal cycle | 9.8 critical | 6.1% | 2016-05-22 |
| CVE-2016-4540 | The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote att… | In your normal cycle | 9.8 critical | 6.1% | 2016-05-22 |
| CVE-2016-4541 | The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote atta… | In your normal cycle | 9.8 critical | 6.1% | 2016-05-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt