CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,286 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,914 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-9936 | The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or… | In your normal cycle | 9.8 critical | 4.3% | 2017-01-04 |
| CVE-2017-7105 | An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue invo… | In your normal cycle | 9.8 critical | 4.3% | 2017-10-23 |
| CVE-2017-7108 | An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue invo… | In your normal cycle | 9.8 critical | 4.3% | 2017-10-23 |
| CVE-2017-7110 | An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue invo… | In your normal cycle | 9.8 critical | 4.3% | 2017-10-23 |
| CVE-2017-7112 | An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue invo… | In your normal cycle | 9.8 critical | 4.3% | 2017-10-23 |
| CVE-2026-67208 | Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by c… | In your normal cycle | 9.8 critical | 4.3% | 2026-07-30 |
| CVE-2016-2297 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to execute arbitrary commands via an "access command shell-like… | In your normal cycle | 9.4 critical | 4.3% | 2016-05-14 |
| CVE-2017-6044 | An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions p… | In your normal cycle | 9.8 critical | 4.3% | 2017-06-30 |
| CVE-2018-8955 | The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remot… | In your normal cycle | 9.8 critical | 4.3% | 2018-10-24 |
| CVE-2020-15357 | Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to execute arbitrary commands via a s… | In your normal cycle | 9.8 critical | 4.3% | 2020-12-11 |
| CVE-2019-8199 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | In your normal cycle | 9.8 critical | 4.3% | 2019-10-17 |
| CVE-2021-34813 | Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup… | In your normal cycle | 9.8 critical | 4.3% | 2021-06-16 |
| CVE-2022-23812 | This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets users with IP located in Russia or… | In your normal cycle | 9.8 critical | 4.3% | 2022-03-16 |
| CVE-2018-18751 | An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_… | In your normal cycle | 9.8 critical | 4.3% | 2018-10-29 |
| CVE-2017-10685 | In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attac… | In your normal cycle | 9.8 critical | 4.3% | 2017-06-29 |
| CVE-2021-42232 | TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the progra… | In your normal cycle | 9.8 critical | 4.3% | 2022-08-23 |
| CVE-2020-28035 | WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. | In your normal cycle | 9.8 critical | 4.3% | 2020-11-02 |
| CVE-2020-5341 | Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data… | In your normal cycle | 9.8 critical | 4.3% | 2021-07-28 |
| CVE-2019-7039 | Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… | In your normal cycle | 9.8 critical | 4.3% | 2019-05-24 |
| CVE-2020-17383 | A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to the device's fi… | In your normal cycle | 9.8 critical | 4.3% | 2022-01-24 |
| CVE-2019-8280 | UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside RAW decoder, which can potentially result code execution. This atta… | In your normal cycle | 9.8 critical | 4.2% | 2019-03-08 |
| CVE-2017-5581 | Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE me… | In your normal cycle | 9.8 critical | 4.2% | 2017-02-28 |
| CVE-2018-11587 | There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php… | In your normal cycle | 9.8 critical | 4.2% | 2018-06-25 |
| CVE-2019-1213 | A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server. An atta… | In your normal cycle | 9.8 critical | 4.2% | 2019-08-14 |
| CVE-2014-9320 | SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges… | In your normal cycle | 9.8 critical | 4.2% | 2021-08-09 |
| CVE-2016-0942 | Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.2% | 2016-01-14 |
| CVE-2016-0944 | Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.2% | 2016-01-14 |
| CVE-2016-0945 | Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.2% | 2016-01-14 |
| CVE-2016-0946 | Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.2% | 2016-01-14 |
| CVE-2017-12796 | The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate users… | In your normal cycle | 9.8 critical | 4.2% | 2017-10-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt