CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,413 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,932 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-8977 | A Remote Denial of Service vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found. | In your normal cycle | 9.1 critical | 4.1% | 2018-02-15 |
| CVE-2020-8125 | Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution… | In your normal cycle | 9.8 critical | 4.1% | 2020-02-04 |
| CVE-2016-9303 | Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code or cause an infinite loop condition when… | In your normal cycle | 9.8 critical | 4.1% | 2017-01-25 |
| CVE-2021-38503 | The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or naviga… | In your normal cycle | 10.0 critical | 4.1% | 2021-12-08 |
| CVE-2020-24264 | Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind… | In your normal cycle | 9.8 critical | 4.1% | 2021-03-16 |
| CVE-2019-12262 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsol… | In your normal cycle | 9.8 critical | 4.1% | 2019-08-14 |
| CVE-2021-44087 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacke… | In your normal cycle | 9.8 critical | 4.1% | 2022-03-17 |
| CVE-2021-37578 | Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for… | In your normal cycle | 9.8 critical | 4.1% | 2021-07-29 |
| CVE-2020-11969 | If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP… | In your normal cycle | 9.8 critical | 4.1% | 2020-06-15 |
| CVE-2018-17786 | On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not require authentication, which… | In your normal cycle | 9.8 critical | 4.1% | 2018-10-02 |
| CVE-2017-12652 | libpng before 1.6.32 does not properly check the length of chunks against the user limit. | In your normal cycle | 9.8 critical | 4.1% | 2019-07-10 |
| CVE-2021-27476 | A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow… | In your normal cycle | 10.0 critical | 4.1% | 2022-03-23 |
| CVE-2015-3431 | Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injectio… | In your normal cycle | 9.8 critical | 4.1% | 2017-09-19 |
| CVE-2017-8227 | Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are detected usi… | In your normal cycle | 9.8 critical | 4.1% | 2019-07-03 |
| CVE-2026-33057 | Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai/… | In your normal cycle | 9.8 critical | 4.1% | 2026-03-20 |
| CVE-2019-3773 | Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (X… | In your normal cycle | 9.8 critical | 4.1% | 2019-01-18 |
| CVE-2019-12164 | ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution. | In your normal cycle | 9.8 critical | 4.1% | 2019-07-23 |
| CVE-2020-17500 | Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web adm… | In your normal cycle | 9.8 critical | 4.1% | 2021-01-07 |
| CVE-2020-28039 | is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a me… | In your normal cycle | 9.1 critical | 4.1% | 2020-11-02 |
| CVE-2017-3791 | A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and execute actions… | In your normal cycle | 10.0 critical | 4.1% | 2017-02-01 |
| CVE-2020-23828 | A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the ho… | In your normal cycle | 9.8 critical | 4.1% | 2020-09-15 |
| CVE-2020-36333 | themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook. | In your normal cycle | 9.1 critical | 4.1% | 2021-05-05 |
| CVE-2017-7062 | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. wa… | In your normal cycle | 9.8 critical | 4.1% | 2017-07-20 |
| CVE-2016-4088 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2021-37832 | A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can i… | In your normal cycle | 9.8 critical | 4.1% | 2021-08-03 |
| CVE-2017-17877 | An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6… | In your normal cycle | 9.8 critical | 4.1% | 2017-12-27 |
| CVE-2023-48777 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder:… | In your normal cycle | 9.9 critical | 4.1% | 2024-03-26 |
| CVE-2019-8205 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | In your normal cycle | 9.8 critical | 4.1% | 2019-10-17 |
| CVE-2019-8211 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | In your normal cycle | 9.8 critical | 4.1% | 2019-10-17 |
| CVE-2019-8212 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | In your normal cycle | 9.8 critical | 4.1% | 2019-10-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt