CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,893 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
36,880 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-7104 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code ex… | In your normal cycle | 9.8 critical | 5.1% | 2019-05-23 |
| CVE-2022-48565 | An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist file… | In your normal cycle | 9.8 critical | 5.1% | 2023-08-22 |
| CVE-2016-6978 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5.1% | 2016-10-13 |
| CVE-2022-47615 | Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. | In your normal cycle | 9.3 critical | 5.1% | 2023-01-26 |
| CVE-2018-12426 | The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation o… | In your normal cycle | 9.8 critical | 5.1% | 2018-07-02 |
| CVE-2017-1000220 | soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution | In your normal cycle | 9.8 critical | 5.1% | 2017-11-17 |
| CVE-2018-0124 | A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain el… | In your normal cycle | 9.8 critical | 5.1% | 2018-02-22 |
| CVE-2017-13997 | A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine E… | In your normal cycle | 9.8 critical | 5.1% | 2017-10-03 |
| CVE-2019-11535 | Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execut… | In your normal cycle | 9.8 critical | 5.1% | 2019-07-17 |
| CVE-2019-7054 | Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… | In your normal cycle | 9.8 critical | 5% | 2019-05-24 |
| CVE-2019-7080 | Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… | In your normal cycle | 9.8 critical | 5% | 2019-05-24 |
| CVE-2017-18046 | Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code… | In your normal cycle | 9.8 critical | 5% | 2018-01-21 |
| CVE-2019-5685 | NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of… | In your normal cycle | 9.8 critical | 5% | 2019-08-06 |
| CVE-2018-19586 | Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core… | In your normal cycle | 9.9 critical | 5% | 2019-04-09 |
| CVE-2014-3244 | XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potenti… | In your normal cycle | 9.8 critical | 5% | 2018-02-01 |
| CVE-2023-2478 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6,… | In your normal cycle | 9.6 critical | 5% | 2023-05-08 |
| CVE-2019-8029 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 5% | 2019-08-20 |
| CVE-2016-4194 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5% | 2016-07-13 |
| CVE-2020-9579 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vul… | In your normal cycle | 9.8 critical | 5% | 2020-06-26 |
| CVE-2020-9580 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vul… | In your normal cycle | 9.8 critical | 5% | 2020-06-26 |
| CVE-2021-26461 | Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment… | In your normal cycle | 9.8 critical | 5% | 2021-06-21 |
| CVE-2016-4211 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5% | 2016-07-13 |
| CVE-2016-4213 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5% | 2016-07-13 |
| CVE-2016-4214 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5% | 2016-07-13 |
| CVE-2016-4252 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5% | 2016-07-13 |
| CVE-2016-4254 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5% | 2016-07-13 |
| CVE-2016-4256 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vector… | In your normal cycle | 9.8 critical | 5% | 2016-09-16 |
| CVE-2016-4257 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vector… | In your normal cycle | 9.8 critical | 5% | 2016-09-16 |
| CVE-2016-4258 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vector… | In your normal cycle | 9.8 critical | 5% | 2016-09-16 |
| CVE-2016-6940 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 5% | 2016-10-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt