CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,984 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,885 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-0150 | A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IO… | In your normal cycle | 9.8 critical | 4.8% | 2018-03-28 |
| CVE-2020-9906 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watch… | In your normal cycle | 9.1 critical | 4.8% | 2020-10-22 |
| CVE-2020-10595 | pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library.… | In your normal cycle | 9.8 critical | 4.8% | 2020-03-31 |
| CVE-2024-7988 | A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code… | In your normal cycle | 9.8 critical | 4.8% | 2024-08-26 |
| CVE-2019-16114 | In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain ac… | In your normal cycle | 9.8 critical | 4.8% | 2019-09-09 |
| CVE-2019-16445 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | In your normal cycle | 9.8 critical | 4.8% | 2019-12-19 |
| CVE-2019-16446 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | In your normal cycle | 9.8 critical | 4.8% | 2019-12-19 |
| CVE-2019-16448 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | In your normal cycle | 9.8 critical | 4.8% | 2019-12-19 |
| CVE-2019-16455 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | In your normal cycle | 9.8 critical | 4.8% | 2019-12-19 |
| CVE-2019-16459 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | In your normal cycle | 9.8 critical | 4.8% | 2019-12-19 |
| CVE-2019-16460 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | In your normal cycle | 9.8 critical | 4.8% | 2019-12-19 |
| CVE-2019-16462 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | In your normal cycle | 9.8 critical | 4.8% | 2019-12-19 |
| CVE-2019-16464 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | In your normal cycle | 9.8 critical | 4.8% | 2019-12-19 |
| CVE-2017-7481 | Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup… | In your normal cycle | 9.8 critical | 4.8% | 2018-07-19 |
| CVE-2023-37483 | SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-… | In your normal cycle | 9.8 critical | 4.8% | 2023-08-08 |
| CVE-2016-8736 | Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack. | In your normal cycle | 9.8 critical | 4.8% | 2017-10-12 |
| CVE-2017-15692 | In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains acces… | In your normal cycle | 9.8 critical | 4.8% | 2018-02-27 |
| CVE-2016-5687 | The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact v… | In your normal cycle | 9.8 critical | 4.8% | 2016-12-13 |
| CVE-2018-14806 | Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrary code. | In your normal cycle | 9.8 critical | 4.8% | 2018-10-23 |
| CVE-2020-1889 | A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in Electron and escalation of pr… | In your normal cycle | 10.0 critical | 4.8% | 2020-09-03 |
| CVE-2019-9569 | Buffer Overflow in dactetra in Delta Controls enteliBUS Manager V3.40_B-571848 allows remote unauthenticated users to execute arbitrary code and possi… | In your normal cycle | 9.8 critical | 4.8% | 2019-08-26 |
| CVE-2020-3801 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and… | In your normal cycle | 9.8 critical | 4.8% | 2020-03-25 |
| CVE-2021-37424 | ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. | In your normal cycle | 9.8 critical | 4.8% | 2021-09-21 |
| CVE-2016-3657 | Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0… | In your normal cycle | 9.8 critical | 4.8% | 2016-04-12 |
| CVE-2013-3316 | Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg". | In your normal cycle | 9.8 critical | 4.8% | 2020-01-29 |
| CVE-2013-3317 | Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key. | In your normal cycle | 9.8 critical | 4.8% | 2020-01-29 |
| CVE-2018-1000613 | Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally… | In your normal cycle | 9.8 critical | 4.8% | 2018-07-09 |
| CVE-2016-9535 | tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mod… | In your normal cycle | 9.8 critical | 4.8% | 2016-11-22 |
| CVE-2017-14375 | EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VA… | In your normal cycle | 9.8 critical | 4.8% | 2017-11-01 |
| CVE-2022-29063 | The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier,… | In your normal cycle | 9.8 critical | 4.8% | 2022-09-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt