CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,941 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,883 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-4259 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vector… | In your normal cycle | 9.8 critical | 4.8% | 2016-09-16 |
| CVE-2016-4260 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vector… | In your normal cycle | 9.8 critical | 4.8% | 2016-09-16 |
| CVE-2016-4261 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vector… | In your normal cycle | 9.8 critical | 4.8% | 2016-09-16 |
| CVE-2016-4262 | Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vector… | In your normal cycle | 9.8 critical | 4.8% | 2016-09-16 |
| CVE-2016-7005 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-10-13 |
| CVE-2016-7006 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-10-13 |
| CVE-2016-7007 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-10-13 |
| CVE-2016-7008 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-10-13 |
| CVE-2016-7009 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-10-13 |
| CVE-2016-7017 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-10-13 |
| CVE-2016-7018 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-10-13 |
| CVE-2016-7019 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-10-13 |
| CVE-2016-4191 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-07-13 |
| CVE-2016-4192 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-07-13 |
| CVE-2016-4193 | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-07-13 |
| CVE-2021-26822 | Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulne… | In your normal cycle | 9.8 critical | 4.8% | 2021-02-15 |
| CVE-2016-1906 | Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not all… | In your normal cycle | 9.8 critical | 4.8% | 2016-02-03 |
| CVE-2019-8262 | UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which results in code execution. Thi… | In your normal cycle | 9.8 critical | 4.8% | 2019-03-05 |
| CVE-2017-6667 | A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthentica… | In your normal cycle | 9.8 critical | 4.8% | 2017-06-13 |
| CVE-2019-19994 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. An attacker without authenticat… | In your normal cycle | 9.8 critical | 4.8% | 2020-02-26 |
| CVE-2001-1496 | Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and poss… | In your normal cycle | 9.8 critical | 4.8% | 2001-12-31 |
| CVE-2016-7853 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.8% | 2016-10-21 |
| CVE-2024-22853 | D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access… | In your normal cycle | 9.8 critical | 4.8% | 2024-02-06 |
| CVE-2017-15697 | A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix… | In your normal cycle | 9.8 critical | 4.8% | 2018-01-23 |
| CVE-2017-12698 | An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a possible au… | In your normal cycle | 9.8 critical | 4.8% | 2017-08-30 |
| CVE-2018-17895 | LAquis SCADA Versions 4.1.0.3870 and prior has several out-of-bounds read vulnerabilities, which may allow remote code execution. | In your normal cycle | 9.8 critical | 4.8% | 2018-10-17 |
| CVE-2021-27185 | The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec. | In your normal cycle | 9.8 critical | 4.8% | 2021-02-10 |
| CVE-2020-26282 | BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Proxy… | In your normal cycle | 10.0 critical | 4.8% | 2020-12-24 |
| CVE-2022-22822 | addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | In your normal cycle | 9.8 critical | 4.8% | 2022-01-10 |
| CVE-2016-1253 | The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote a… | In your normal cycle | 9.8 critical | 4.8% | 2017-12-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt