CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,173 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,902 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-7084 | Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… | In your normal cycle | 9.8 critical | 4.4% | 2019-05-24 |
| CVE-2019-7086 | Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… | In your normal cycle | 9.8 critical | 4.4% | 2019-05-24 |
| CVE-2019-7087 | Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… | In your normal cycle | 9.8 critical | 4.4% | 2019-05-24 |
| CVE-2018-14495 | Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-… | In your normal cycle | 9.8 critical | 4.4% | 2019-07-10 |
| CVE-2017-16042 | Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrar… | In your normal cycle | 9.8 critical | 4.4% | 2018-06-04 |
| CVE-2020-5413 | Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default op… | In your normal cycle | 9.8 critical | 4.4% | 2020-07-31 |
| CVE-2022-23122 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit… | In your normal cycle | 9.8 critical | 4.4% | 2023-03-28 |
| CVE-2019-11035 | When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past… | In your normal cycle | 9.1 critical | 4.4% | 2019-04-18 |
| CVE-2018-1000544 | rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary f… | In your normal cycle | 9.8 critical | 4.4% | 2018-06-26 |
| CVE-2026-58479 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows… | In your normal cycle | 9.8 critical | 4.4% | 2026-07-14 |
| CVE-2021-46454 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanApcliSettings. This vulnera… | In your normal cycle | 9.8 critical | 4.4% | 2022-02-04 |
| CVE-2020-24561 | A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system.… | In your normal cycle | 9.1 critical | 4.4% | 2020-09-15 |
| CVE-2018-11692 | An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /… | In your normal cycle | 9.8 critical | 4.4% | 2018-06-04 |
| CVE-2015-9551 | An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution… | In your normal cycle | 9.8 critical | 4.4% | 2020-11-24 |
| CVE-2021-34079 | OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in th… | In your normal cycle | 9.8 critical | 4.4% | 2022-06-02 |
| CVE-2019-3397 | Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.… | In your normal cycle | 9.1 critical | 4.4% | 2019-06-03 |
| CVE-2017-5154 | An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed i… | In your normal cycle | 9.8 critical | 4.4% | 2017-02-13 |
| CVE-2018-4331 | A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watc… | In your normal cycle | 9.8 critical | 4.4% | 2019-04-03 |
| CVE-2017-16634 | In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method. | In your normal cycle | 9.8 critical | 4.4% | 2017-11-10 |
| CVE-2024-8381 | A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vu… | In your normal cycle | 9.8 critical | 4.4% | 2024-09-03 |
| CVE-2017-7279 | An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued… | In your normal cycle | 9.8 critical | 4.4% | 2017-04-12 |
| CVE-2026-0545 | In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` ap… | In your normal cycle | 9.8 critical | 4.4% | 2026-04-03 |
| CVE-2021-45733 | TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability… | In your normal cycle | 9.8 critical | 4.4% | 2022-02-04 |
| CVE-2021-45738 | TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerabil… | In your normal cycle | 9.8 critical | 4.4% | 2022-02-04 |
| CVE-2025-6424 | A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox… | In your normal cycle | 9.8 critical | 4.4% | 2025-06-24 |
| CVE-2019-12994 | Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL. | In your normal cycle | 9.1 critical | 4.4% | 2019-08-08 |
| CVE-2016-11017 | The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via s… | In your normal cycle | 9.8 critical | 4.4% | 2020-01-06 |
| CVE-2019-17415 | A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute a… | In your normal cycle | 9.8 critical | 4.4% | 2019-10-09 |
| CVE-2021-1138 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary… | In your normal cycle | 9.8 critical | 4.4% | 2021-01-20 |
| CVE-2021-1140 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary… | In your normal cycle | 9.8 critical | 4.4% | 2021-01-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt