CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,883 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-10920 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen pa… | In your normal cycle | 9.8 critical | 4.9% | 2020-07-23 |
| CVE-2020-14497 | Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled stri… | In your normal cycle | 9.8 critical | 4.9% | 2020-07-15 |
| CVE-2008-0961 | EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface. | In your normal cycle | 9.8 critical | 4.9% | 2008-04-14 |
| CVE-2016-6288 | The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or po… | In your normal cycle | 9.8 critical | 4.9% | 2016-07-25 |
| CVE-2022-20711 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | In your normal cycle | 10.0 critical | 4.9% | 2022-02-10 |
| CVE-2020-13873 | A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authentication) to… | In your normal cycle | 9.8 critical | 4.9% | 2021-05-12 |
| CVE-2024-23052 | An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the… | In your normal cycle | 9.8 critical | 4.9% | 2024-02-29 |
| CVE-2019-13551 | Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path p… | In your normal cycle | 9.8 critical | 4.9% | 2019-10-31 |
| CVE-2021-26810 | D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in… | In your normal cycle | 9.8 critical | 4.9% | 2021-03-30 |
| CVE-2019-16943 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a… | In your normal cycle | 9.8 critical | 4.9% | 2019-10-01 |
| CVE-2016-6441 | A vulnerability in the Transaction Language 1 (TL1) code of Cisco ASR 900 Series routers could allow an unauthenticated, remote attacker to cause a re… | In your normal cycle | 9.8 critical | 4.9% | 2016-11-03 |
| CVE-2021-41816 | CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such a… | In your normal cycle | 9.8 critical | 4.9% | 2022-02-06 |
| CVE-2019-12929 | The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achieve code execution, denial of… | In your normal cycle | 9.8 critical | 4.9% | 2019-06-24 |
| CVE-2021-41097 | aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-pat… | In your normal cycle | 9.1 critical | 4.9% | 2021-09-27 |
| CVE-2019-8003 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 4.9% | 2019-08-20 |
| CVE-2019-8030 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 4.9% | 2019-08-20 |
| CVE-2019-8031 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 4.9% | 2019-08-20 |
| CVE-2019-8036 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 4.9% | 2019-08-20 |
| CVE-2020-3775 | Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful explo… | In your normal cycle | 9.8 critical | 4.9% | 2020-03-25 |
| CVE-2020-3783 | Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a heap corruption vulnerability. Successful exp… | In your normal cycle | 9.8 critical | 4.9% | 2020-03-25 |
| CVE-2020-3792 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and… | In your normal cycle | 9.8 critical | 4.9% | 2020-03-25 |
| CVE-2020-3793 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and… | In your normal cycle | 9.8 critical | 4.9% | 2020-03-25 |
| CVE-2020-14507 | Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbi… | In your normal cycle | 9.8 critical | 4.9% | 2020-07-15 |
| CVE-2024-39250 | EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface. | In your normal cycle | 9.8 critical | 4.9% | 2024-07-22 |
| CVE-2019-18580 | Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated… | In your normal cycle | 10.0 critical | 4.9% | 2019-11-26 |
| CVE-2016-5556 | Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability via… | In your normal cycle | 9.6 critical | 4.9% | 2016-10-25 |
| CVE-2025-2505 | The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This… | In your normal cycle | 9.8 critical | 4.9% | 2025-03-20 |
| CVE-2024-37051 | GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023… | In your normal cycle | 9.3 critical | 4.9% | 2024-06-10 |
| CVE-2021-23344 | The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set. | In your normal cycle | 9.8 critical | 4.9% | 2021-03-04 |
| CVE-2020-29552 | An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring,… | In your normal cycle | 9.8 critical | 4.9% | 2020-12-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt