CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,851 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,871 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-18903 | Vanilla 2.6.x before 2.6.4 allows remote code execution. | In your normal cycle | 9.8 critical | 5.2% | 2018-11-03 |
| CVE-2024-3191 | A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the c… | In your normal cycle | 9.8 critical | 5.2% | 2024-04-29 |
| CVE-2017-2785 | An exploitable buffer overflow exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be s… | In your normal cycle | 10.0 critical | 5.2% | 2017-03-10 |
| CVE-2017-7778 | A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uniniti… | In your normal cycle | 9.8 critical | 5.2% | 2018-06-11 |
| CVE-2018-16850 | postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpos… | In your normal cycle | 9.8 critical | 5.2% | 2018-11-13 |
| CVE-2020-35949 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload a… | In your normal cycle | 10.0 critical | 5.1% | 2021-01-01 |
| CVE-2016-2339 | An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In Fiddle::Function.new "in… | In your normal cycle | 9.8 critical | 5.1% | 2017-01-06 |
| CVE-2020-12856 | OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to… | In your normal cycle | 9.8 critical | 5.1% | 2020-05-18 |
| CVE-2021-46067 | In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover. | In your normal cycle | 9.8 critical | 5.1% | 2022-01-06 |
| CVE-2019-3980 | The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be ex… | In your normal cycle | 9.8 critical | 5.1% | 2019-10-08 |
| CVE-2022-38296 | Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager. | In your normal cycle | 9.8 critical | 5.1% | 2022-09-12 |
| CVE-2020-2546 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - JavaEE). Supported versions that a… | In your normal cycle | 9.8 critical | 5.1% | 2020-01-15 |
| CVE-2017-17480 | In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-boun… | In your normal cycle | 9.8 critical | 5.1% | 2017-12-08 |
| CVE-2019-16941 | NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is… | In your normal cycle | 9.8 critical | 5.1% | 2019-09-28 |
| CVE-2017-16100 | dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible. | In your normal cycle | 9.8 critical | 5.1% | 2018-06-07 |
| CVE-2019-13116 | The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, relat… | In your normal cycle | 9.8 critical | 5.1% | 2019-10-16 |
| CVE-2025-71243 | The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. A… | In your normal cycle | 9.8 critical | 5.1% | 2026-02-19 |
| CVE-2020-28050 | Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server. | In your normal cycle | 9.1 critical | 5.1% | 2021-03-05 |
| CVE-2023-45136 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When document names are validated according t… | In your normal cycle | 9.6 critical | 5.1% | 2023-10-25 |
| CVE-2016-6902 | lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands. | In your normal cycle | 9.9 critical | 5.1% | 2017-04-24 |
| CVE-2016-2031 | Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient che… | In your normal cycle | 9.8 critical | 5.1% | 2020-01-31 |
| CVE-2017-8408 | An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings rec… | In your normal cycle | 9.8 critical | 5.1% | 2019-07-02 |
| CVE-2019-5396 | A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | In your normal cycle | 9.4 critical | 5.1% | 2019-08-09 |
| CVE-2018-12048 | A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi via vectors involving /portal_… | In your normal cycle | 9.8 critical | 5.1% | 2018-06-08 |
| CVE-2018-12049 | A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.cgi via vectors involving /port… | In your normal cycle | 9.8 critical | 5.1% | 2018-06-08 |
| CVE-2020-15865 | A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the r… | In your normal cycle | 9.8 critical | 5.1% | 2020-08-18 |
| CVE-2020-6061 | An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST r… | In your normal cycle | 9.8 critical | 5.1% | 2020-02-19 |
| CVE-2019-7112 | Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and e… | In your normal cycle | 9.8 critical | 5.1% | 2019-05-23 |
| CVE-2019-20477 | PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a c… | In your normal cycle | 9.8 critical | 5.1% | 2020-02-19 |
| CVE-2020-24633 | There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets dest… | In your normal cycle | 9.8 critical | 5.1% | 2020-12-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt