CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,557 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
36,944 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-27269 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the c… | In your normal cycle | 9.8 critical | 3.8% | 2022-04-10 |
| CVE-2016-3606 | Unspecified vulnerability in Oracle Java SE 7u101 and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and… | In your normal cycle | 9.6 critical | 3.8% | 2016-07-21 |
| CVE-2016-9138 | PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial… | In your normal cycle | 9.8 critical | 3.8% | 2017-01-04 |
| CVE-2020-28971 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unaut… | In your normal cycle | 9.8 critical | 3.8% | 2020-12-01 |
| CVE-2017-6821 | Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors… | In your normal cycle | 9.8 critical | 3.8% | 2017-05-23 |
| CVE-2021-3918 | json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | In your normal cycle | 9.8 critical | 3.8% | 2021-11-13 |
| CVE-2021-27462 | A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies se… | In your normal cycle | 10.0 critical | 3.8% | 2022-03-23 |
| CVE-2021-27470 | A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies se… | In your normal cycle | 10.0 critical | 3.8% | 2022-03-23 |
| CVE-2019-8009 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 3.8% | 2019-08-20 |
| CVE-2019-8098 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 3.8% | 2019-08-20 |
| CVE-2019-8100 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | In your normal cycle | 9.8 critical | 3.8% | 2019-08-20 |
| CVE-2022-1531 | SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerabili… | In your normal cycle | 9.8 critical | 3.8% | 2022-04-29 |
| CVE-2022-3477 | The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does… | In your normal cycle | 9.8 critical | 3.8% | 2022-11-14 |
| CVE-2017-16523 | MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices have a zyad1234 password for the zyad1234 account, which is equivalen… | In your normal cycle | 9.8 critical | 3.8% | 2017-11-03 |
| CVE-2022-32839 | The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catali… | In your normal cycle | 9.8 critical | 3.8% | 2022-08-24 |
| CVE-2023-26326 | The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated att… | In your normal cycle | 9.8 critical | 3.8% | 2023-02-23 |
| CVE-2017-13139 | In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk. | In your normal cycle | 9.8 critical | 3.8% | 2017-08-23 |
| CVE-2019-7165 | A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code. | In your normal cycle | 9.8 critical | 3.8% | 2019-07-03 |
| CVE-2019-13192 | Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute… | In your normal cycle | 9.8 critical | 3.8% | 2020-03-13 |
| CVE-2016-9942 | Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application cr… | In your normal cycle | 9.8 critical | 3.8% | 2016-12-31 |
| CVE-2018-1000881 | Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedA… | In your normal cycle | 9.8 critical | 3.8% | 2018-12-20 |
| CVE-2018-8871 | In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based buffer overflow vulnerability, w… | In your normal cycle | 9.8 critical | 3.8% | 2018-05-25 |
| CVE-2025-55423 | A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-… | In your normal cycle | 9.8 critical | 3.8% | 2026-01-20 |
| CVE-2024-34257 | TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands… | In your normal cycle | 9.8 critical | 3.8% | 2024-05-08 |
| CVE-2022-23123 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to… | In your normal cycle | 9.8 critical | 3.8% | 2023-03-28 |
| CVE-2016-4819 | The printfDx function in Takumi Yamada DX Library for Borland C++ 3.13f through 3.16b, DX Library for Gnu C++ 3.13f through 3.16b, and DX Library for… | In your normal cycle | 9.8 critical | 3.8% | 2016-06-19 |
| CVE-2019-10104 | In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the defaul… | In your normal cycle | 9.8 critical | 3.8% | 2019-07-03 |
| CVE-2022-37452 | Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set. | In your normal cycle | 9.8 critical | 3.8% | 2022-08-07 |
| CVE-2022-22845 | QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' ins… | In your normal cycle | 9.8 critical | 3.8% | 2022-01-10 |
| CVE-2025-71210 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected… | In your normal cycle | 9.8 critical | 3.8% | 2026-05-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt