CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,173 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,902 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-11017 | The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via s… | In your normal cycle | 9.8 critical | 4.4% | 2020-01-06 |
| CVE-2019-17415 | A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute a… | In your normal cycle | 9.8 critical | 4.4% | 2019-10-09 |
| CVE-2021-1138 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary… | In your normal cycle | 9.8 critical | 4.4% | 2021-01-20 |
| CVE-2021-1140 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary… | In your normal cycle | 9.8 critical | 4.4% | 2021-01-20 |
| CVE-2017-7912 | Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attack… | In your normal cycle | 9.8 critical | 4.4% | 2019-04-08 |
| CVE-2016-4373 | The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a cra… | In your normal cycle | 9.8 critical | 4.4% | 2016-08-01 |
| CVE-2021-46229 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_paswd.asp. This vulnerability… | In your normal cycle | 9.8 critical | 4.4% | 2022-02-04 |
| CVE-2025-52053 | TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter.… | In your normal cycle | 9.8 critical | 4.4% | 2025-09-15 |
| CVE-2021-44676 | Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of… | In your normal cycle | 9.8 critical | 4.4% | 2021-12-20 |
| CVE-2019-8025 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 4.4% | 2019-08-20 |
| CVE-2019-8047 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 4.4% | 2019-08-20 |
| CVE-2016-1112 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.4% | 2016-05-11 |
| CVE-2019-13573 | A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of… | In your normal cycle | 9.8 critical | 4.4% | 2019-07-17 |
| CVE-2017-12177 | xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to cra… | In your normal cycle | 9.8 critical | 4.4% | 2018-01-24 |
| CVE-2017-12179 | xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X se… | In your normal cycle | 9.8 critical | 4.4% | 2018-01-24 |
| CVE-2014-6617 | Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00 contains a hardcoded password for the root account, which allows remote attackers to… | In your normal cycle | 9.8 critical | 4.4% | 2018-03-09 |
| CVE-2020-6990 | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix… | In your normal cycle | 9.8 critical | 4.4% | 2020-03-16 |
| CVE-2020-21935 | A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to… | In your normal cycle | 9.8 critical | 4.4% | 2021-07-21 |
| CVE-2021-42875 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.s… | In your normal cycle | 9.8 critical | 4.4% | 2022-06-02 |
| CVE-2016-9961 | game-music-emu before 0.6.1 mishandles unspecified integer values. | In your normal cycle | 9.8 critical | 4.4% | 2017-06-06 |
| CVE-2015-0244 | PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while r… | In your normal cycle | 9.8 critical | 4.4% | 2020-01-27 |
| CVE-2020-7632 | node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument. | In your normal cycle | 9.8 critical | 4.4% | 2020-04-06 |
| CVE-2019-1010257 | An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. A UR… | In your normal cycle | 9.1 critical | 4.4% | 2019-03-27 |
| CVE-2026-56415 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A rem… | In your normal cycle | 10.0 critical | 4.4% | 2026-06-30 |
| CVE-2025-71334 | Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflow… | In your normal cycle | 9.8 critical | 4.4% | 2026-06-25 |
| CVE-2018-10388 | Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execu… | In your normal cycle | 9.8 critical | 4.4% | 2019-12-23 |
| CVE-2019-5390 | A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | In your normal cycle | 9.8 critical | 4.4% | 2019-06-05 |
| CVE-2025-5947 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including,… | In your normal cycle | 9.8 critical | 4.4% | 2025-08-01 |
| CVE-2021-23901 | An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external… | In your normal cycle | 9.1 critical | 4.4% | 2021-01-25 |
| CVE-2017-8105 | FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in… | In your normal cycle | 9.8 critical | 4.4% | 2017-04-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt