CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,415 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,932 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-8213 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | In your normal cycle | 9.8 critical | 4.1% | 2019-10-17 |
| CVE-2019-8214 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | In your normal cycle | 9.8 critical | 4.1% | 2019-10-17 |
| CVE-2019-8215 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | In your normal cycle | 9.8 critical | 4.1% | 2019-10-17 |
| CVE-2019-8220 | Adobe Acrobat and Reader versions, 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and… | In your normal cycle | 9.8 critical | 4.1% | 2019-10-17 |
| CVE-2019-8221 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… | In your normal cycle | 9.8 critical | 4.1% | 2019-10-17 |
| CVE-2018-0310 | A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker… | In your normal cycle | 9.8 critical | 4.1% | 2018-06-21 |
| CVE-2020-29658 | Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation. | In your normal cycle | 9.8 critical | 4.1% | 2021-03-05 |
| CVE-2024-46627 | Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests. | In your normal cycle | 9.1 critical | 4.1% | 2024-09-26 |
| CVE-2020-17368 | Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection. | In your normal cycle | 9.8 critical | 4.1% | 2020-08-11 |
| CVE-2017-5396 | A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from m… | In your normal cycle | 9.8 critical | 4.1% | 2018-06-11 |
| CVE-2019-11034 | When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past… | In your normal cycle | 9.1 critical | 4.1% | 2019-04-18 |
| CVE-2019-14893 | A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of mal… | In your normal cycle | 9.8 critical | 4.1% | 2020-03-02 |
| CVE-2016-5274 | Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thund… | In your normal cycle | 9.8 critical | 4.1% | 2016-09-22 |
| CVE-2013-7070 | The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharact… | In your normal cycle | 9.8 critical | 4.1% | 2019-12-31 |
| CVE-2018-20162 | Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypas… | In your normal cycle | 9.9 critical | 4.1% | 2019-03-21 |
| CVE-2021-30179 | Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are han… | In your normal cycle | 9.8 critical | 4.1% | 2021-06-01 |
| CVE-2019-7101 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code ex… | In your normal cycle | 9.8 critical | 4.1% | 2019-05-23 |
| CVE-2019-7102 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code ex… | In your normal cycle | 9.8 critical | 4.1% | 2019-05-23 |
| CVE-2017-8807 | vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sens… | In your normal cycle | 9.1 critical | 4.1% | 2017-11-16 |
| CVE-2019-11768 | An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an S… | In your normal cycle | 9.8 critical | 4.1% | 2019-06-05 |
| CVE-2019-3940 | Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerab… | In your normal cycle | 9.8 critical | 4.1% | 2019-04-09 |
| CVE-2020-10824 | A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 al… | In your normal cycle | 9.8 critical | 4.1% | 2020-03-26 |
| CVE-2020-10825 | A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices b… | In your normal cycle | 9.8 critical | 4.1% | 2020-03-26 |
| CVE-2024-8425 | The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_w… | In your normal cycle | 9.8 critical | 4.1% | 2025-02-28 |
| CVE-2022-32533 | Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setti… | In your normal cycle | 9.8 critical | 4.1% | 2022-07-06 |
| CVE-2018-12805 | Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability. Successful exploitation could lead to privilege escalation. | In your normal cycle | 9.8 critical | 4.1% | 2018-07-20 |
| CVE-2016-4089 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2016-4090 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2016-4093 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2016-4094 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt