CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,769 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,848 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-8011 | Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (dae… | In your normal cycle | 9.8 critical | 5.5% | 2020-01-28 |
| CVE-2016-9063 | An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50. | In your normal cycle | 9.8 critical | 5.5% | 2018-06-11 |
| CVE-2021-1994 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10… | In your normal cycle | 9.8 critical | 5.5% | 2021-01-20 |
| CVE-2017-5511 | coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which triggers a heap-based buffer over… | In your normal cycle | 9.8 critical | 5.5% | 2017-03-24 |
| CVE-2019-7261 | Linear eMerge E3-Series devices have Hard-coded Credentials. | In your normal cycle | 9.8 critical | 5.5% | 2019-07-02 |
| CVE-2015-4116 | Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP before 5.5.27 and 5.6.x before 5.6.11 allows remote atta… | In your normal cycle | 9.8 critical | 5.5% | 2016-05-16 |
| CVE-2025-52046 | Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc paramet… | In your normal cycle | 9.8 critical | 5.5% | 2025-07-17 |
| CVE-2022-30284 | In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arg… | In your normal cycle | 9.0 critical | 5.5% | 2022-05-04 |
| CVE-2025-55190 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0… | In your normal cycle | 9.9 critical | 5.5% | 2025-09-04 |
| CVE-2022-27005 | Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the… | In your normal cycle | 9.8 critical | 5.5% | 2022-03-15 |
| CVE-2019-7040 | Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… | In your normal cycle | 9.8 critical | 5.5% | 2019-05-24 |
| CVE-2026-21877 | n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code usi… | In your normal cycle | 9.9 critical | 5.4% | 2026-01-08 |
| CVE-2018-8027 | Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor. | In your normal cycle | 9.8 critical | 5.4% | 2018-07-31 |
| CVE-2023-25725 | HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." T… | In your normal cycle | 9.1 critical | 5.4% | 2023-02-14 |
| CVE-2016-4167 | Adobe DNG Software Development Kit (SDK) before 1.4 2016 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) v… | In your normal cycle | 9.8 critical | 5.4% | 2016-06-16 |
| CVE-2016-5689 | The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of NULL poin… | In your normal cycle | 9.8 critical | 5.4% | 2016-12-13 |
| CVE-2020-1747 | A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes u… | In your normal cycle | 9.8 critical | 5.4% | 2020-03-24 |
| CVE-2019-16463 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | In your normal cycle | 9.8 critical | 5.4% | 2019-12-19 |
| CVE-2015-3249 | The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access… | In your normal cycle | 9.8 critical | 5.4% | 2017-10-30 |
| CVE-2016-3493 | Unspecified vulnerability in the Hyperion Financial Reporting component in Oracle Hyperion 11.1.2.4 allows remote attackers to affect confidentiality,… | In your normal cycle | 9.8 critical | 5.4% | 2016-07-21 |
| CVE-2021-20991 | In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command inj… | In your normal cycle | 9.8 critical | 5.4% | 2021-04-19 |
| CVE-2016-5582 | Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri… | In your normal cycle | 9.6 critical | 5.4% | 2016-10-25 |
| CVE-2019-11831 | The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which al… | In your normal cycle | 9.8 critical | 5.4% | 2019-05-09 |
| CVE-2019-18839 | FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to f… | In your normal cycle | 9.0 critical | 5.4% | 2019-11-13 |
| CVE-2018-18319 | An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has a… | In your normal cycle | 9.8 critical | 5.4% | 2018-10-15 |
| CVE-2019-18283 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without aut… | In your normal cycle | 9.8 critical | 5.4% | 2019-12-12 |
| CVE-2018-10628 | AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a specially… | In your normal cycle | 9.8 critical | 5.4% | 2018-07-24 |
| CVE-2021-34993 | This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not re… | In your normal cycle | 9.8 critical | 5.4% | 2022-01-13 |
| CVE-2022-45063 | xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within t… | In your normal cycle | 9.8 critical | 5.4% | 2022-11-10 |
| CVE-2021-1293 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allo… | In your normal cycle | 9.8 critical | 5.4% | 2021-02-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt