CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,672 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
36,466 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-15921 EXP | Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as C… | Patch early | 9.8 critical | 18.3% | 2020-07-24 |
| CVE-2016-0954 EXP | Adobe Digital Editions before 4.5.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vector… | Patch early | 9.8 critical | 18.3% | 2016-03-09 |
| CVE-2001-0609 EXP | Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply… | Patch early | 9.8 critical | 18.2% | 2001-08-02 |
| CVE-2018-15137 EXP | CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code exe… | Patch early | 9.8 critical | 18.2% | 2018-08-08 |
| CVE-2019-8041 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 17.9% | 2019-08-20 |
| CVE-2019-8046 EXP | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… | Patch early | 9.8 critical | 17.9% | 2019-08-20 |
| CVE-2018-11741 EXP | NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOT… | Patch early | 9.8 critical | 17.9% | 2018-12-26 |
| CVE-2016-4204 EXP | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 17.8% | 2016-07-13 |
| CVE-2016-4208 EXP | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 17.8% | 2016-07-13 |
| CVE-2016-4206 EXP | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 17.8% | 2016-07-13 |
| CVE-2016-4205 EXP | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 17.8% | 2016-07-13 |
| CVE-2016-4207 EXP | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 17.8% | 2016-07-13 |
| CVE-2015-2279 EXP | cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows remote attackers to execute a… | Patch early | 9.8 critical | 17.6% | 2017-07-25 |
| CVE-2019-9083 EXP | SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued. | Patch early | 9.8 critical | 17.6% | 2019-03-21 |
| CVE-2022-4395 EXP | The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbit… | Patch early | 9.8 critical | 17.6% | 2023-01-30 |
| CVE-2017-5135 EXP | Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. The Technicolor (formerly Cisco… | Patch early | 9.1 critical | 17.5% | 2017-04-27 |
| CVE-2026-21876 EXP | The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 a… | Patch early | 9.3 critical | 17.5% | 2026-01-08 |
| CVE-2016-1077 EXP | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… | Patch early | 9.8 critical | 17.4% | 2016-05-11 |
| CVE-2023-26602 EXP | ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmp… | Patch early | 9.8 critical | 17.4% | 2023-02-26 |
| CVE-2021-24040 EXP | Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input,… | Patch early | 9.8 critical | 17.4% | 2021-09-10 |
| CVE-2017-5447 EXP | An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an att… | Patch early | 9.1 critical | 17.3% | 2018-06-11 |
| CVE-2019-6543 EXP | AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update.… | Patch early | 9.8 critical | 17.3% | 2019-02-13 |
| CVE-2017-5404 EXP | A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This… | Patch early | 9.8 critical | 17.3% | 2018-06-11 |
| CVE-2018-13859 EXP | MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, allow unauthorized remote attacke… | Patch early | 9.8 critical | 17.2% | 2018-07-17 |
| CVE-2018-6546 EXP | plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes co… | Patch early | 9.8 critical | 17.2% | 2018-04-13 |
| CVE-2024-6209 EXP | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to ac… | Patch early | 10.0 critical | 17.2% | 2024-07-05 |
| CVE-2017-14244 EXP | An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access a… | Patch early | 9.8 critical | 17.1% | 2017-09-17 |
| CVE-2018-13981 EXP | The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default com… | Patch early | 9.8 critical | 17.1% | 2018-07-16 |
| CVE-2019-1912 EXP | A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to u… | Patch early | 9.1 critical | 17% | 2019-08-07 |
| CVE-2019-8641 EXP | An out-of-bounds read was addressed with improved input validation. | Patch early | 9.8 critical | 17% | 2019-12-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt