CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,883 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-10684 | In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attac… | In your normal cycle | 9.8 critical | 4.9% | 2017-06-29 |
| CVE-2020-13109 | Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted packet data to the built-in m… | In your normal cycle | 9.8 critical | 4.9% | 2020-05-16 |
| CVE-2019-10789 | All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanit… | In your normal cycle | 9.8 critical | 4.9% | 2020-02-06 |
| CVE-2013-1751 | TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl bac… | In your normal cycle | 9.8 critical | 4.9% | 2019-11-07 |
| CVE-2026-2017 | A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurityHandler of the file /goform/wx… | In your normal cycle | 9.8 critical | 4.9% | 2026-02-06 |
| CVE-2024-11639 | An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access | In your normal cycle | 10.0 critical | 4.9% | 2024-12-10 |
| CVE-2019-3463 | Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to p… | In your normal cycle | 9.8 critical | 4.9% | 2019-02-06 |
| CVE-2016-6646 | The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.… | In your normal cycle | 9.8 critical | 4.9% | 2016-10-05 |
| CVE-2018-11410 | An issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTranslationTable.c allows remote attackers to cause a… | In your normal cycle | 9.8 critical | 4.9% | 2018-05-24 |
| CVE-2018-15497 | The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this… | In your normal cycle | 9.8 critical | 4.9% | 2018-10-23 |
| CVE-2020-27160 | Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior… | In your normal cycle | 9.8 critical | 4.9% | 2020-10-27 |
| CVE-2019-5600 | In FreeBSD 12.0-STABLE before r349622, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349624, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELE… | In your normal cycle | 9.8 critical | 4.9% | 2019-07-03 |
| CVE-2017-4918 | VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful expl… | In your normal cycle | 9.8 critical | 4.9% | 2017-06-08 |
| CVE-2019-7252 | Linear eMerge E3-Series devices have Default Credentials. | In your normal cycle | 9.8 critical | 4.9% | 2019-07-02 |
| CVE-2023-40057 | The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an… | In your normal cycle | 9.0 critical | 4.9% | 2024-02-15 |
| CVE-2019-1651 | A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condit… | In your normal cycle | 9.9 critical | 4.9% | 2019-01-24 |
| CVE-2020-3743 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… | In your normal cycle | 9.8 critical | 4.9% | 2020-02-13 |
| CVE-2020-3745 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… | In your normal cycle | 9.8 critical | 4.9% | 2020-02-13 |
| CVE-2020-3746 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… | In your normal cycle | 9.8 critical | 4.9% | 2020-02-13 |
| CVE-2020-3749 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… | In your normal cycle | 9.8 critical | 4.9% | 2020-02-13 |
| CVE-2020-3750 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… | In your normal cycle | 9.8 critical | 4.9% | 2020-02-13 |
| CVE-2020-3751 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… | In your normal cycle | 9.8 critical | 4.9% | 2020-02-13 |
| CVE-2020-3754 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… | In your normal cycle | 9.8 critical | 4.9% | 2020-02-13 |
| CVE-2022-36536 | An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escala… | In your normal cycle | 9.8 critical | 4.9% | 2022-09-16 |
| CVE-2014-9846 | Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact. | In your normal cycle | 9.8 critical | 4.9% | 2017-03-20 |
| CVE-2020-24383 | An issue was discovered in FNET through 4.6.4. The code for processing resource records in mDNS queries doesn't check for proper '\0' termination of t… | In your normal cycle | 9.1 critical | 4.9% | 2020-12-11 |
| CVE-2021-21016 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful… | In your normal cycle | 9.1 critical | 4.9% | 2021-02-11 |
| CVE-2017-16610 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not… | In your normal cycle | 9.8 critical | 4.8% | 2018-01-23 |
| CVE-2016-7134 | ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of serv… | In your normal cycle | 9.8 critical | 4.8% | 2016-09-12 |
| CVE-2016-4250 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-07-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt