CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,593 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,835 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-4542 | The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct sppri… | In your normal cycle | 9.8 critical | 6.1% | 2016-05-22 |
| CVE-2016-7161 | Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code o… | In your normal cycle | 9.8 critical | 6.1% | 2016-10-05 |
| CVE-2017-13983 | An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remo… | In your normal cycle | 9.8 critical | 6.1% | 2017-09-30 |
| CVE-2021-21872 | An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A speci… | In your normal cycle | 9.9 critical | 6.1% | 2021-12-22 |
| CVE-2021-21883 | An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-c… | In your normal cycle | 9.9 critical | 6.1% | 2021-12-22 |
| CVE-2018-18314 | Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | In your normal cycle | 9.8 critical | 6.1% | 2018-12-07 |
| CVE-2014-4172 | A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2… | In your normal cycle | 9.8 critical | 6.1% | 2020-01-24 |
| CVE-2018-14643 | An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execu… | In your normal cycle | 9.8 critical | 6.1% | 2018-09-21 |
| CVE-2018-5474 | Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to execute arbitrar… | In your normal cycle | 9.8 critical | 6.1% | 2018-03-26 |
| CVE-2019-8060 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 6% | 2019-08-20 |
| CVE-2019-9762 | A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authe… | In your normal cycle | 9.8 critical | 6% | 2019-03-14 |
| CVE-2021-37608 | Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache… | In your normal cycle | 9.8 critical | 6% | 2021-08-18 |
| CVE-2021-45029 | Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | In your normal cycle | 9.8 critical | 6% | 2022-01-25 |
| CVE-2014-9906 | Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary co… | In your normal cycle | 9.8 critical | 6% | 2016-08-19 |
| CVE-2026-20180 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying… | In your normal cycle | 9.9 critical | 6% | 2026-04-15 |
| CVE-2019-10910 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this c… | In your normal cycle | 9.8 critical | 6% | 2019-05-16 |
| CVE-2020-14972 | Multiple SQL injection vulnerabilities in Sourcecodester Pisay Online E-Learning System 1.0 allow remote unauthenticated attackers to bypass authentic… | In your normal cycle | 9.8 critical | 6% | 2020-06-22 |
| CVE-2020-9691 | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lea… | In your normal cycle | 9.6 critical | 6% | 2020-07-29 |
| CVE-2020-1042 | A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user o… | In your normal cycle | 9.0 critical | 6% | 2020-07-14 |
| CVE-2022-42484 | An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead… | In your normal cycle | 9.8 critical | 6% | 2023-01-30 |
| CVE-2023-6825 | The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free… | In your normal cycle | 9.9 critical | 6% | 2024-03-13 |
| CVE-2019-16453 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | In your normal cycle | 9.8 critical | 6% | 2019-12-19 |
| CVE-2022-43325 | An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows at… | In your normal cycle | 9.8 critical | 6% | 2022-12-02 |
| CVE-2020-6016 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_ReceiveUnreliable… | In your normal cycle | 9.8 critical | 6% | 2020-11-18 |
| CVE-2015-4642 | The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attacke… | In your normal cycle | 9.8 critical | 6% | 2016-05-16 |
| CVE-2017-5204 | The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print(). | In your normal cycle | 9.8 critical | 6% | 2017-01-28 |
| CVE-2024-29868 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery m… | In your normal cycle | 9.1 critical | 6% | 2024-06-24 |
| CVE-2021-45966 | An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.pl allows remote attackers to e… | In your normal cycle | 9.8 critical | 6% | 2022-03-18 |
| CVE-2016-1930 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allow remote attackers to c… | In your normal cycle | 9.8 critical | 6% | 2016-01-31 |
| CVE-2017-14476 | In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially craft… | In your normal cycle | 9.8 critical | 6% | 2018-05-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt