CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,461 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,936 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-3797 | Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and… | In your normal cycle | 9.8 critical | 3.9% | 2020-03-25 |
| CVE-2018-15168 | A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynam… | In your normal cycle | 9.8 critical | 3.9% | 2018-08-08 |
| CVE-2021-33816 | The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, an… | In your normal cycle | 9.8 critical | 3.9% | 2021-11-10 |
| CVE-2020-9039 | Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and… | In your normal cycle | 9.8 critical | 3.9% | 2020-02-22 |
| CVE-2021-32983 | A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The… | In your normal cycle | 9.8 critical | 3.9% | 2021-08-30 |
| CVE-2020-6141 | An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL in… | In your normal cycle | 9.8 critical | 3.9% | 2020-09-01 |
| CVE-2019-10878 | In Teeworlds 0.7.2, there is a failed bounds check in CDataFileReader::GetData() and CDataFileReader::ReplaceData() and related functions in engine/sh… | In your normal cycle | 9.8 critical | 3.9% | 2019-04-05 |
| CVE-2020-12007 | A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a des… | In your normal cycle | 9.8 critical | 3.9% | 2020-07-16 |
| CVE-2019-9898 | Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71. | In your normal cycle | 9.8 critical | 3.9% | 2019-03-21 |
| CVE-2020-2040 | A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with r… | In your normal cycle | 9.8 critical | 3.9% | 2020-09-09 |
| CVE-2016-7983 | The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print(). | In your normal cycle | 9.8 critical | 3.9% | 2017-01-28 |
| CVE-2016-7489 | Teradata Virtual Machine Community Edition v15.10's perl script /opt/teradata/gsctools/bin/t2a.pl creates files in /tmp in an insecure manner, this ma… | In your normal cycle | 9.8 critical | 3.9% | 2016-11-10 |
| CVE-2018-20432 | D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to ga… | In your normal cycle | 9.8 critical | 3.9% | 2020-09-14 |
| CVE-2014-9841 | The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "… | In your normal cycle | 9.8 critical | 3.9% | 2017-03-20 |
| CVE-2014-9843 | The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors. | In your normal cycle | 9.8 critical | 3.9% | 2017-03-20 |
| CVE-2017-1000009 | Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution. | In your normal cycle | 9.8 critical | 3.9% | 2017-07-17 |
| CVE-2019-8948 | PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163. | In your normal cycle | 9.8 critical | 3.9% | 2019-02-20 |
| CVE-2022-29130 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | In your normal cycle | 9.8 critical | 3.9% | 2022-05-10 |
| CVE-2016-5062 | The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to… | In your normal cycle | 9.8 critical | 3.9% | 2016-09-29 |
| CVE-2011-2717 | The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacha… | In your normal cycle | 9.8 critical | 3.9% | 2019-11-27 |
| CVE-2017-8415 | An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the pass… | In your normal cycle | 9.8 critical | 3.9% | 2019-07-02 |
| CVE-2015-7029 | Apple AirPort Base Station Firmware before 7.6.7 and 7.7.x before 7.7.7 misparses DNS data, which allows remote attackers to execute arbitrary code or… | In your normal cycle | 9.8 critical | 3.9% | 2016-07-03 |
| CVE-2015-7425 | The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectr… | In your normal cycle | 10.0 critical | 3.9% | 2016-02-21 |
| CVE-2021-27646 | Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute… | In your normal cycle | 9.8 critical | 3.9% | 2021-03-12 |
| CVE-2019-8268 | UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadString functi… | In your normal cycle | 9.8 critical | 3.9% | 2019-03-08 |
| CVE-2019-8272 | UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution. This attack appears… | In your normal cycle | 9.8 critical | 3.9% | 2019-03-08 |
| CVE-2023-6320 | A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A seri… | In your normal cycle | 9.1 critical | 3.9% | 2024-04-09 |
| CVE-2018-1000042 | Security Onion Solutions Squert version 1.3.0 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS C… | In your normal cycle | 9.8 critical | 3.9% | 2018-02-09 |
| CVE-2018-1000043 | Security Onion Solutions Squert version 1.0.1 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS C… | In your normal cycle | 9.8 critical | 3.9% | 2018-02-09 |
| CVE-2018-5488 | NetApp SANtricity Web Services Proxy versions 1.10.x000.0002 through 2.12.X000.0002 and SANtricity Storage Manager 11.30.0X00.0004 through 11.42.0X00.… | In your normal cycle | 9.8 critical | 3.9% | 2018-06-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt