CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,660 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,839 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-9582 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabilit… | In your normal cycle | 9.8 critical | 5.7% | 2020-06-26 |
| CVE-2020-9583 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabilit… | In your normal cycle | 9.8 critical | 5.7% | 2020-06-26 |
| CVE-2016-15042 | The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file upload… | In your normal cycle | 9.8 critical | 5.7% | 2024-10-16 |
| CVE-2019-8015 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 5.7% | 2019-08-20 |
| CVE-2020-23151 | rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed di… | In your normal cycle | 9.8 critical | 5.7% | 2021-08-09 |
| CVE-2016-4537 | The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale… | In your normal cycle | 9.8 critical | 5.7% | 2016-05-22 |
| CVE-2016-1040 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5.7% | 2016-05-11 |
| CVE-2020-15049 | An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can su… | In your normal cycle | 9.9 critical | 5.7% | 2020-06-30 |
| CVE-2017-14632 | Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi-… | In your normal cycle | 9.8 critical | 5.7% | 2017-09-21 |
| CVE-2016-6948 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5.7% | 2016-10-13 |
| CVE-2019-11062 | The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploi… | In your normal cycle | 9.8 critical | 5.7% | 2019-07-11 |
| CVE-2026-73034 | DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the se… | In your normal cycle | 9.8 critical | 5.7% | 2026-08-11 |
| CVE-2021-30120 | Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of serve… | In your normal cycle | 9.9 critical | 5.7% | 2021-07-09 |
| CVE-2026-19586 | A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insuff… | In your normal cycle | 9.8 critical | 5.7% | 2026-08-20 |
| CVE-2010-5305 | The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5x… | In your normal cycle | 9.8 critical | 5.7% | 2019-03-26 |
| CVE-2016-6254 | Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a… | In your normal cycle | 9.1 critical | 5.7% | 2016-08-19 |
| CVE-2022-26210 | Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185… | In your normal cycle | 9.8 critical | 5.7% | 2022-03-15 |
| CVE-2024-36412 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events… | In your normal cycle | 10.0 critical | 5.7% | 2024-06-10 |
| CVE-2018-19417 | An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT PUBLISH messages with a variab… | In your normal cycle | 10.0 critical | 5.7% | 2018-11-21 |
| CVE-2017-10352 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is af… | In your normal cycle | 9.9 critical | 5.7% | 2017-10-19 |
| CVE-2021-40146 | A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulne… | In your normal cycle | 9.8 critical | 5.7% | 2021-09-11 |
| CVE-2018-19707 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… | In your normal cycle | 9.8 critical | 5.7% | 2019-01-18 |
| CVE-2018-19708 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… | In your normal cycle | 9.8 critical | 5.7% | 2019-01-18 |
| CVE-2018-19715 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… | In your normal cycle | 9.8 critical | 5.7% | 2019-01-18 |
| CVE-2018-16036 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… | In your normal cycle | 9.8 critical | 5.7% | 2019-01-18 |
| CVE-2018-16037 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… | In your normal cycle | 9.8 critical | 5.7% | 2019-01-18 |
| CVE-2018-16039 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… | In your normal cycle | 9.8 critical | 5.7% | 2019-01-18 |
| CVE-2018-16040 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… | In your normal cycle | 9.8 critical | 5.7% | 2019-01-18 |
| CVE-2015-9262 | _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a… | In your normal cycle | 9.8 critical | 5.7% | 2018-08-01 |
| CVE-2017-8857 | In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote command executio… | In your normal cycle | 9.8 critical | 5.7% | 2017-05-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt