CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,461 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,936 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-4328 | MEDHOST Perioperative Information Management System (aka PIMS or VPIMS) before 2015R1 has hardcoded credentials, which makes it easier for remote atta… | In your normal cycle | 9.8 critical | 4% | 2016-06-10 |
| CVE-2016-2024 | HPE Insight Control before 7.5.1 allow remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vec… | In your normal cycle | 9.8 critical | 4% | 2016-06-08 |
| CVE-2021-33267 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… | In your normal cycle | 9.8 critical | 4% | 2021-12-01 |
| CVE-2021-33269 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… | In your normal cycle | 9.8 critical | 4% | 2021-12-01 |
| CVE-2021-33270 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… | In your normal cycle | 9.8 critical | 4% | 2021-12-01 |
| CVE-2021-33271 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… | In your normal cycle | 9.8 critical | 4% | 2021-12-01 |
| CVE-2021-33274 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… | In your normal cycle | 9.8 critical | 4% | 2021-12-01 |
| CVE-2016-3527 | Unspecified vulnerability in the Oracle Demand Planning component in Oracle Supply Chain Products Suite 12.1 and 12.2 allows remote attackers to affec… | In your normal cycle | 9.1 critical | 4% | 2016-07-21 |
| CVE-2016-3546 | Unspecified vulnerability in the Oracle Advanced Collections component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers t… | In your normal cycle | 9.1 critical | 4% | 2016-07-21 |
| CVE-2016-10128 | Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x bef… | In your normal cycle | 9.8 critical | 4% | 2017-03-24 |
| CVE-2017-1000372 | A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using setui… | In your normal cycle | 9.8 critical | 4% | 2017-06-19 |
| CVE-2020-9630 | Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerabi… | In your normal cycle | 9.8 critical | 4% | 2020-06-26 |
| CVE-2019-11061 | A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT device… | In your normal cycle | 10.0 critical | 4% | 2019-08-29 |
| CVE-2017-2519 | An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… | In your normal cycle | 9.8 critical | 4% | 2017-05-22 |
| CVE-2021-20125 | An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect… | In your normal cycle | 9.8 critical | 3.9% | 2021-10-13 |
| CVE-2018-7800 | A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to the device… | In your normal cycle | 9.8 critical | 3.9% | 2018-12-24 |
| CVE-2015-8804 | x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-3… | In your normal cycle | 9.8 critical | 3.9% | 2016-02-23 |
| CVE-2022-3481 | The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a RE… | In your normal cycle | 9.8 critical | 3.9% | 2022-11-07 |
| CVE-2022-26186 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi. | In your normal cycle | 9.8 critical | 3.9% | 2022-03-22 |
| CVE-2021-24220 | Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPre… | In your normal cycle | 9.1 critical | 3.9% | 2021-04-12 |
| CVE-2018-5188 | Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume… | In your normal cycle | 9.8 critical | 3.9% | 2018-10-18 |
| CVE-2020-28940 | On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unaut… | In your normal cycle | 9.8 critical | 3.9% | 2020-12-01 |
| CVE-2020-28970 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unaut… | In your normal cycle | 9.8 critical | 3.9% | 2020-12-01 |
| CVE-2020-27853 | Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a format string… | In your normal cycle | 9.8 critical | 3.9% | 2020-10-27 |
| CVE-2020-3784 | Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful e… | In your normal cycle | 9.8 critical | 3.9% | 2020-03-25 |
| CVE-2020-3785 | Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful e… | In your normal cycle | 9.8 critical | 3.9% | 2020-03-25 |
| CVE-2020-3786 | Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful e… | In your normal cycle | 9.8 critical | 3.9% | 2020-03-25 |
| CVE-2020-3787 | Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful e… | In your normal cycle | 9.8 critical | 3.9% | 2020-03-25 |
| CVE-2020-3788 | Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful e… | In your normal cycle | 9.8 critical | 3.9% | 2020-03-25 |
| CVE-2020-3789 | Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful e… | In your normal cycle | 9.8 critical | 3.9% | 2020-03-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt