CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,373 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
36,927 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-3795 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and… | In your normal cycle | 9.8 critical | 4.2% | 2020-03-25 |
| CVE-2020-7624 | effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument. | In your normal cycle | 9.8 critical | 4.2% | 2020-04-02 |
| CVE-2020-7625 | op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function. | In your normal cycle | 9.8 critical | 4.2% | 2020-04-02 |
| CVE-2020-7627 | node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'exec… | In your normal cycle | 9.8 critical | 4.2% | 2020-04-02 |
| CVE-2020-7629 | install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument. | In your normal cycle | 9.8 critical | 4.2% | 2020-04-02 |
| CVE-2020-7630 | git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument. | In your normal cycle | 9.8 critical | 4.2% | 2020-04-02 |
| CVE-2019-7731 | MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database f… | In your normal cycle | 9.8 critical | 4.2% | 2019-02-11 |
| CVE-2021-42740 | The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex desig… | In your normal cycle | 9.8 critical | 4.2% | 2021-10-21 |
| CVE-2013-5615 | The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does no… | In your normal cycle | 9.8 critical | 4.2% | 2013-12-11 |
| CVE-2022-4093 | SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many… | In your normal cycle | 9.8 critical | 4.2% | 2022-11-21 |
| CVE-2011-1517 | SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted… | In your normal cycle | 9.8 critical | 4.2% | 2020-02-05 |
| CVE-2023-37903 | vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to esca… | In your normal cycle | 9.8 critical | 4.2% | 2023-07-21 |
| CVE-2023-43373 | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php. | In your normal cycle | 9.8 critical | 4.2% | 2023-09-20 |
| CVE-2021-21014 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful ex… | In your normal cycle | 9.1 critical | 4.2% | 2021-02-11 |
| CVE-2019-6260 | The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which… | In your normal cycle | 9.8 critical | 4.2% | 2019-01-22 |
| CVE-2020-5311 | libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow. | In your normal cycle | 9.8 critical | 4.2% | 2020-01-03 |
| CVE-2015-8803 | The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementa… | In your normal cycle | 9.8 critical | 4.2% | 2016-02-23 |
| CVE-2018-5095 | An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results… | In your normal cycle | 9.8 critical | 4.2% | 2018-06-11 |
| CVE-2018-5439 | A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arbi… | In your normal cycle | 9.8 critical | 4.2% | 2018-02-19 |
| CVE-2017-8020 | An issue was discovered in EMC ScaleIO 2.0.1.x. A buffer overflow vulnerability in the SDBG service may potentially allow a remote unauthenticated att… | In your normal cycle | 9.8 critical | 4.2% | 2017-11-28 |
| CVE-2017-3761 | The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this c… | In your normal cycle | 9.8 critical | 4.2% | 2017-10-17 |
| CVE-2024-44902 | A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. | In your normal cycle | 9.8 critical | 4.2% | 2024-09-09 |
| CVE-2020-36109 | ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can… | In your normal cycle | 9.8 critical | 4.2% | 2021-02-01 |
| CVE-2020-5647 | Improper access control vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version ’05.65… | In your normal cycle | 9.8 critical | 4.2% | 2020-11-06 |
| CVE-2019-12328 | A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP phone with… | In your normal cycle | 9.0 critical | 4.2% | 2019-07-22 |
| CVE-2020-15692 | In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that wi… | In your normal cycle | 9.8 critical | 4.2% | 2020-08-14 |
| CVE-2020-15533 | In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to una… | In your normal cycle | 9.8 critical | 4.2% | 2020-10-01 |
| CVE-2020-15715 | rConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error in the search.crud.php script.… | In your normal cycle | 9.9 critical | 4.2% | 2020-07-28 |
| CVE-2015-7517 | Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary… | In your normal cycle | 9.8 critical | 4.2% | 2017-08-29 |
| CVE-2016-3556 | Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect co… | In your normal cycle | 9.8 critical | 4.2% | 2016-07-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt