peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,415 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,932 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-4096 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.1% 2016-05-11
CVE-2016-4097 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.1% 2016-05-11
CVE-2016-4098 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.1% 2016-05-11
CVE-2016-4099 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.1% 2016-05-11
CVE-2016-4100 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.1% 2016-05-11
CVE-2016-4101 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.1% 2016-05-11
CVE-2016-4103 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.1% 2016-05-11
CVE-2016-4104 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.1% 2016-05-11
CVE-2016-4105 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.1% 2016-05-11
CVE-2018-6320 A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Polic… In your normal cycle 9.8 critical 4.1% 2018-09-06
CVE-2019-10122 eQ-3 HomeMatic CCU2 devices before 2.41.9 and CCU3 devices before 3.43.16 have buffer overflows in the ReGa ise GmbH HTTP-Server 2.0 component, aka HM… In your normal cycle 9.8 critical 4.1% 2019-07-10
CVE-2022-40189 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflo… In your normal cycle 9.8 critical 4.1% 2022-11-22
CVE-2016-6554 Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default crede… In your normal cycle 9.8 critical 4.1% 2018-07-13
CVE-2021-42313 Microsoft Defender for IoT Remote Code Execution Vulnerability In your normal cycle 10.0 critical 4.1% 2021-12-15
CVE-2018-20305 D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass parameter. In the /goform/form2usercon… In your normal cycle 9.8 critical 4.1% 2018-12-20
CVE-2019-8257 Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… In your normal cycle 9.8 critical 4.1% 2020-01-28
CVE-2018-0016 Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interface of a Junos OS device may result in a kernel cr… In your normal cycle 9.8 critical 4.1% 2018-04-11
CVE-2019-11040 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below… In your normal cycle 9.1 critical 4.1% 2019-06-19
CVE-2021-33268 D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… In your normal cycle 9.8 critical 4.1% 2021-12-01
CVE-2017-8786 pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact… In your normal cycle 9.8 critical 4.1% 2017-05-05
CVE-2018-10103 tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2). In your normal cycle 9.8 critical 4.1% 2019-10-03
CVE-2017-14851 A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authenticat… In your normal cycle 9.8 critical 4.1% 2019-06-03
CVE-2023-39650 Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single. In your normal cycle 9.8 critical 4.1% 2023-08-28
CVE-2018-14496 Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_b… In your normal cycle 9.8 critical 4.1% 2019-07-10
CVE-2016-9676 Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors. In your normal cycle 9.8 critical 4.1% 2017-01-18
CVE-2021-45459 lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter. In your normal cycle 9.8 critical 4.1% 2021-12-22
CVE-2018-1000525 openpsa contains a PHP Object Injection vulnerability in Form data passed as GET request variables that can result in Possible information disclosure… In your normal cycle 9.8 critical 4.1% 2018-06-26
CVE-2016-8606 The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack. In your normal cycle 9.8 critical 4.1% 2017-01-12
CVE-2020-15591 fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution). In your normal cycle 9.8 critical 4.1% 2022-03-17
CVE-2016-1984 The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes… In your normal cycle 9.8 critical 4.1% 2016-01-22
← previous page 226 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt