CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,429 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,936 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-14352 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters… | In your normal cycle | 9.8 critical | 4% | 2018-07-17 |
| CVE-2021-30351 | An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto, Snapdrag… | In your normal cycle | 9.8 critical | 4% | 2022-01-03 |
| CVE-2019-13082 | Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before… | In your normal cycle | 9.8 critical | 4% | 2019-06-30 |
| CVE-2016-4095 | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… | In your normal cycle | 9.8 critical | 4% | 2016-11-10 |
| CVE-2018-10589 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcce… | In your normal cycle | 9.8 critical | 4% | 2018-05-15 |
| CVE-2017-7575 | Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the application-protection password via a \x00\x01\x00\x00\x0… | In your normal cycle | 9.8 critical | 4% | 2017-04-06 |
| CVE-2020-8636 | An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution . | In your normal cycle | 9.8 critical | 4% | 2020-02-06 |
| CVE-2019-8256 | ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitati… | In your normal cycle | 9.8 critical | 4% | 2019-12-19 |
| CVE-2022-34970 | Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows a… | In your normal cycle | 9.8 critical | 4% | 2022-08-04 |
| CVE-2022-50596 | D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability within the web management interf… | In your normal cycle | 9.8 critical | 4% | 2025-11-06 |
| CVE-2018-11058 | RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior… | In your normal cycle | 9.8 critical | 4% | 2018-09-14 |
| CVE-2020-15860 | Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute… | In your normal cycle | 9.9 critical | 4% | 2020-07-24 |
| CVE-2021-31217 | In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM. | In your normal cycle | 9.1 critical | 4% | 2021-07-13 |
| CVE-2022-20749 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | In your normal cycle | 10.0 critical | 4% | 2022-02-10 |
| CVE-2026-61498 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unau… | In your normal cycle | 9.8 critical | 4% | 2026-07-13 |
| CVE-2016-5277 | Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.… | In your normal cycle | 9.8 critical | 4% | 2016-09-22 |
| CVE-2023-50089 | A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs duri… | In your normal cycle | 9.8 critical | 4% | 2023-12-15 |
| CVE-2012-10054 | Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a… | In your normal cycle | 9.8 critical | 4% | 2025-08-13 |
| CVE-2018-0320 | A vulnerability in the web framework code of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to execute a… | In your normal cycle | 9.8 critical | 4% | 2018-06-07 |
| CVE-2023-46265 | An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF). | In your normal cycle | 9.8 critical | 4% | 2023-12-19 |
| CVE-2021-43907 | Visual Studio Code WSL Extension Remote Code Execution Vulnerability | In your normal cycle | 9.8 critical | 4% | 2021-12-15 |
| CVE-2024-47533 | Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability st… | In your normal cycle | 9.8 critical | 4% | 2024-11-18 |
| CVE-2018-11466 | A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4.… | In your normal cycle | 9.8 critical | 4% | 2018-12-12 |
| CVE-2019-15609 | The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability. | In your normal cycle | 9.8 critical | 4% | 2020-02-28 |
| CVE-2021-36364 | Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards. | In your normal cycle | 9.8 critical | 4% | 2021-09-28 |
| CVE-2021-36366 | Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards. | In your normal cycle | 9.8 critical | 4% | 2021-09-28 |
| CVE-2016-5799 | Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which m… | In your normal cycle | 9.8 critical | 4% | 2016-08-24 |
| CVE-2018-3785 | A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter. | In your normal cycle | 9.8 critical | 4% | 2018-08-17 |
| CVE-2020-9671 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead… | In your normal cycle | 9.8 critical | 4% | 2020-07-17 |
| CVE-2019-19594 | reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute… | In your normal cycle | 9.8 critical | 4% | 2019-12-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt