CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,226 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,903 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-33329 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network… | In your normal cycle | 9.8 critical | 4.3% | 2022-06-30 |
| CVE-2014-5415 | Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain acce… | In your normal cycle | 9.1 critical | 4.3% | 2016-10-05 |
| CVE-2020-7626 | karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument. | In your normal cycle | 9.8 critical | 4.3% | 2020-04-02 |
| CVE-2019-18830 | Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functiona… | In your normal cycle | 9.8 critical | 4.3% | 2019-12-16 |
| CVE-2017-14265 | A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote denia… | In your normal cycle | 9.8 critical | 4.3% | 2017-09-11 |
| CVE-2019-8006 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 4.3% | 2019-08-20 |
| CVE-2019-8026 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 4.3% | 2019-08-20 |
| CVE-2019-8028 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 4.3% | 2019-08-20 |
| CVE-2019-8055 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 4.3% | 2019-08-20 |
| CVE-2019-8061 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 4.3% | 2019-08-20 |
| CVE-2017-16931 | parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the c… | In your normal cycle | 9.8 critical | 4.3% | 2017-11-23 |
| CVE-2023-48316 | Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote c… | In your normal cycle | 9.8 critical | 4.3% | 2023-12-05 |
| CVE-2015-7510 | Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd. | In your normal cycle | 9.8 critical | 4.3% | 2017-09-25 |
| CVE-2022-20210 | The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the modem parses it and fills in inter… | In your normal cycle | 9.8 critical | 4.3% | 2022-06-15 |
| CVE-2017-14323 | SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information,… | In your normal cycle | 9.8 critical | 4.3% | 2018-04-10 |
| CVE-2026-4170 | A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/managem… | In your normal cycle | 9.8 critical | 4.3% | 2026-03-16 |
| CVE-2020-19001 | Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/… | In your normal cycle | 9.8 critical | 4.3% | 2021-08-27 |
| CVE-2019-16450 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | In your normal cycle | 9.8 critical | 4.3% | 2019-12-19 |
| CVE-2019-16454 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… | In your normal cycle | 9.8 critical | 4.3% | 2019-12-19 |
| CVE-2015-9271 | The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw… | In your normal cycle | 9.8 critical | 4.3% | 2018-10-04 |
| CVE-2025-59951 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The official Docker image for Termix ve… | In your normal cycle | 9.1 critical | 4.3% | 2025-10-01 |
| CVE-2018-21268 | The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the… | In your normal cycle | 10.0 critical | 4.3% | 2020-06-25 |
| CVE-2024-7854 | The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to insufficient escaping on the user… | In your normal cycle | 10.0 critical | 4.3% | 2024-08-21 |
| CVE-2018-16184 | RICOH Interactive Whiteboard D2200 V1.6 to V2.2, D5500 V1.6 to V2.2, D5510 V1.6 to V2.2, and the display versions with RICOH Interactive Whiteboard Co… | In your normal cycle | 9.8 critical | 4.3% | 2019-01-09 |
| CVE-2012-10060 | Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long use… | In your normal cycle | 9.8 critical | 4.3% | 2025-08-13 |
| CVE-2018-17317 | FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the io_mode, ap_mode,… | In your normal cycle | 9.8 critical | 4.3% | 2018-09-21 |
| CVE-2019-15504 | drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usb… | In your normal cycle | 9.8 critical | 4.3% | 2019-08-23 |
| CVE-2024-29204 | A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arb… | In your normal cycle | 9.8 critical | 4.3% | 2024-04-19 |
| CVE-2020-9682 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to ar… | In your normal cycle | 9.8 critical | 4.3% | 2020-07-17 |
| CVE-2022-38627 | Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vul… | In your normal cycle | 9.8 critical | 4.3% | 2023-01-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt