CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,415 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,932 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-4096 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2016-4097 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2016-4098 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2016-4099 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2016-4100 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2016-4101 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2016-4103 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2016-4104 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2016-4105 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4.1% | 2016-05-11 |
| CVE-2018-6320 | A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Polic… | In your normal cycle | 9.8 critical | 4.1% | 2018-09-06 |
| CVE-2019-10122 | eQ-3 HomeMatic CCU2 devices before 2.41.9 and CCU3 devices before 3.43.16 have buffer overflows in the ReGa ise GmbH HTTP-Server 2.0 component, aka HM… | In your normal cycle | 9.8 critical | 4.1% | 2019-07-10 |
| CVE-2022-40189 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflo… | In your normal cycle | 9.8 critical | 4.1% | 2022-11-22 |
| CVE-2016-6554 | Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default crede… | In your normal cycle | 9.8 critical | 4.1% | 2018-07-13 |
| CVE-2021-42313 | Microsoft Defender for IoT Remote Code Execution Vulnerability | In your normal cycle | 10.0 critical | 4.1% | 2021-12-15 |
| CVE-2018-20305 | D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass parameter. In the /goform/form2usercon… | In your normal cycle | 9.8 critical | 4.1% | 2018-12-20 |
| CVE-2019-8257 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 4.1% | 2020-01-28 |
| CVE-2018-0016 | Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interface of a Junos OS device may result in a kernel cr… | In your normal cycle | 9.8 critical | 4.1% | 2018-04-11 |
| CVE-2019-11040 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below… | In your normal cycle | 9.1 critical | 4.1% | 2019-06-19 |
| CVE-2021-33268 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… | In your normal cycle | 9.8 critical | 4.1% | 2021-12-01 |
| CVE-2017-8786 | pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact… | In your normal cycle | 9.8 critical | 4.1% | 2017-05-05 |
| CVE-2018-10103 | tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2). | In your normal cycle | 9.8 critical | 4.1% | 2019-10-03 |
| CVE-2017-14851 | A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authenticat… | In your normal cycle | 9.8 critical | 4.1% | 2019-06-03 |
| CVE-2023-39650 | Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single. | In your normal cycle | 9.8 critical | 4.1% | 2023-08-28 |
| CVE-2018-14496 | Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_b… | In your normal cycle | 9.8 critical | 4.1% | 2019-07-10 |
| CVE-2016-9676 | Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors. | In your normal cycle | 9.8 critical | 4.1% | 2017-01-18 |
| CVE-2021-45459 | lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter. | In your normal cycle | 9.8 critical | 4.1% | 2021-12-22 |
| CVE-2018-1000525 | openpsa contains a PHP Object Injection vulnerability in Form data passed as GET request variables that can result in Possible information disclosure… | In your normal cycle | 9.8 critical | 4.1% | 2018-06-26 |
| CVE-2016-8606 | The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack. | In your normal cycle | 9.8 critical | 4.1% | 2017-01-12 |
| CVE-2020-15591 | fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution). | In your normal cycle | 9.8 critical | 4.1% | 2022-03-17 |
| CVE-2016-1984 | The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes… | In your normal cycle | 9.8 critical | 4.1% | 2016-01-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt