CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,599 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,836 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-8271 | The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code. | In your normal cycle | 9.8 critical | 5.9% | 2017-04-13 |
| CVE-2017-3184 | ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset page… | In your normal cycle | 9.8 critical | 5.9% | 2017-12-16 |
| CVE-2022-28032 | AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php | In your normal cycle | 9.8 critical | 5.9% | 2022-04-12 |
| CVE-2018-1000301 | curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl… | In your normal cycle | 9.1 critical | 5.9% | 2018-05-24 |
| CVE-2019-8070 | Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability. Successful exploitation could… | In your normal cycle | 9.8 critical | 5.9% | 2019-09-12 |
| CVE-2017-17790 | The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by… | In your normal cycle | 9.8 critical | 5.9% | 2017-12-20 |
| CVE-2021-28797 | A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerabilit… | In your normal cycle | 9.8 critical | 5.9% | 2021-04-14 |
| CVE-2017-12883 | Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to discl… | In your normal cycle | 9.1 critical | 5.9% | 2017-09-19 |
| CVE-2016-1621 | libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary cod… | In your normal cycle | 9.8 critical | 5.9% | 2016-03-12 |
| CVE-2020-8899 | There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, un… | In your normal cycle | 9.8 critical | 5.9% | 2020-05-06 |
| CVE-2019-5477 | A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Proc… | In your normal cycle | 9.8 critical | 5.9% | 2019-08-16 |
| CVE-2020-5723 | The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords… | In your normal cycle | 9.8 critical | 5.9% | 2020-03-30 |
| CVE-2018-5473 | An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices running firmware… | In your normal cycle | 9.8 critical | 5.9% | 2018-02-19 |
| CVE-2018-0314 | A vulnerability in the Cisco Fabric Services (CFS) component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote at… | In your normal cycle | 9.8 critical | 5.9% | 2018-06-20 |
| CVE-2022-1950 | The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to… | In your normal cycle | 9.8 critical | 5.9% | 2022-08-01 |
| CVE-2019-1010268 | Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, r… | In your normal cycle | 9.8 critical | 5.9% | 2019-07-18 |
| CVE-2017-8023 | EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsrex… | In your normal cycle | 9.8 critical | 5.9% | 2019-04-01 |
| CVE-2024-39762 | Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specia… | In your normal cycle | 9.1 critical | 5.9% | 2025-01-14 |
| CVE-2025-60724 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | In your normal cycle | 9.8 critical | 5.9% | 2025-11-11 |
| CVE-2016-1074 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5.9% | 2016-05-11 |
| CVE-2021-34684 | Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and… | In your normal cycle | 9.8 critical | 5.9% | 2021-11-08 |
| CVE-2019-5953 | Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspeci… | In your normal cycle | 9.8 critical | 5.9% | 2019-05-17 |
| CVE-2020-13576 | A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to… | In your normal cycle | 9.8 critical | 5.9% | 2021-02-10 |
| CVE-2018-4124 | An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13.3 Supplemental Update is affected. tvOS before 11… | In your normal cycle | 9.8 critical | 5.9% | 2018-04-03 |
| CVE-2020-1025 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation… | In your normal cycle | 9.8 critical | 5.9% | 2020-07-14 |
| CVE-2017-11295 | An issue was discovered in Adobe DNG Converter 9.12.1 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploita… | In your normal cycle | 9.8 critical | 5.9% | 2017-12-09 |
| CVE-2025-14709 | A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin/… | In your normal cycle | 9.8 critical | 5.9% | 2025-12-15 |
| CVE-2018-7081 | A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit… | In your normal cycle | 9.8 critical | 5.9% | 2019-09-13 |
| CVE-2022-0715 | A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leake… | In your normal cycle | 9.1 critical | 5.8% | 2022-03-09 |
| CVE-2019-9945 | SoftNAS Cloud 4.2.0 and 4.2.1 allows remote command execution. The NGINX default configuration file has a check to verify the status of a user cookie.… | In your normal cycle | 9.8 critical | 5.8% | 2019-03-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt