CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,674 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,840 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-61511 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the t… | In your normal cycle | 9.8 critical | 5.6% | 2026-07-27 |
| CVE-2018-8845 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcce… | In your normal cycle | 9.8 critical | 5.6% | 2018-05-15 |
| CVE-2022-24702 | An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution vi… | In your normal cycle | 9.8 critical | 5.6% | 2022-06-02 |
| CVE-2015-8367 | The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory… | In your normal cycle | 9.8 critical | 5.6% | 2020-01-14 |
| CVE-2021-24741 | The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, c… | In your normal cycle | 9.8 critical | 5.6% | 2021-09-20 |
| CVE-2016-4265 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5.6% | 2016-08-26 |
| CVE-2016-4266 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5.6% | 2016-08-26 |
| CVE-2016-4268 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5.6% | 2016-08-26 |
| CVE-2016-4269 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5.6% | 2016-08-26 |
| CVE-2016-4270 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5.6% | 2016-08-26 |
| CVE-2026-20186 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying… | In your normal cycle | 9.9 critical | 5.6% | 2026-04-15 |
| CVE-2019-7020 | Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… | In your normal cycle | 9.8 critical | 5.6% | 2019-05-24 |
| CVE-2019-7085 | Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… | In your normal cycle | 9.8 critical | 5.6% | 2019-05-24 |
| CVE-2021-27856 | FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privil… | In your normal cycle | 9.8 critical | 5.6% | 2021-12-15 |
| CVE-2016-6291 | The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers… | In your normal cycle | 9.8 critical | 5.6% | 2016-07-25 |
| CVE-2016-6813 | Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is ab… | In your normal cycle | 9.8 critical | 5.6% | 2018-02-06 |
| CVE-2020-14100 | In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator… | In your normal cycle | 9.8 critical | 5.6% | 2020-09-11 |
| CVE-2018-17141 | HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit ena… | In your normal cycle | 9.8 critical | 5.6% | 2018-09-21 |
| CVE-2018-0308 | A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker… | In your normal cycle | 9.8 critical | 5.6% | 2018-06-20 |
| CVE-2018-0312 | A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker… | In your normal cycle | 9.8 critical | 5.6% | 2018-06-20 |
| CVE-2017-16926 | Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker (… | In your normal cycle | 9.8 critical | 5.6% | 2017-11-22 |
| CVE-2024-5535 | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory cont… | In your normal cycle | 9.1 critical | 5.6% | 2024-06-27 |
| CVE-2016-1363 | Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through… | In your normal cycle | 9.8 critical | 5.6% | 2016-04-21 |
| CVE-2021-33885 | An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unauthenticated attacker to… | In your normal cycle | 10.0 critical | 5.6% | 2021-08-25 |
| CVE-2017-5897 | The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags i… | In your normal cycle | 9.8 critical | 5.6% | 2017-03-23 |
| CVE-2024-3673 | The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inc… | In your normal cycle | 9.1 critical | 5.6% | 2024-08-30 |
| CVE-2022-29774 | iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal. | In your normal cycle | 9.8 critical | 5.6% | 2022-06-21 |
| CVE-2025-14346 | WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pai… | In your normal cycle | 9.8 critical | 5.6% | 2026-01-05 |
| CVE-2020-10917 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not requi… | In your normal cycle | 9.8 critical | 5.6% | 2020-07-22 |
| CVE-2014-5044 | Multiple integer overflows in libgfortran might allow remote attackers to execute arbitrary code or cause a denial of service (Fortran application cra… | In your normal cycle | 9.8 critical | 5.6% | 2018-03-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt