CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,436 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-26
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-40684 KEV EXP | An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiPr… | Patch first | 9.8 critical | 100% | 2022-10-18 |
| CVE-2025-0282 KEV EXP | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for Z… | Patch first | 9.0 critical | 100% | 2025-01-08 |
| CVE-2024-4879 KEV EXP | ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerabilit… | Patch first | 9.8 critical | 100% | 2024-07-10 |
| CVE-2025-31161 KEV EXP | CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is use… | Patch first | 9.8 critical | 100% | 2025-04-03 |
| CVE-2014-8361 KEV EXP | The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the… | Patch first | 9.8 critical | 100% | 2015-05-01 |
| CVE-2022-47986 KEV EXP | IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserializat… | Patch first | 9.8 critical | 100% | 2023-02-17 |
| CVE-2021-42013 KEV EXP | It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs… | Patch first | 9.8 critical | 100% | 2021-10-07 |
| CVE-2019-2725 KEV EXP | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected a… | Patch first | 9.8 critical | 100% | 2019-04-26 |
| CVE-2019-10149 KEV EXP | A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c m… | Patch first | 9.8 critical | 100% | 2019-06-05 |
| CVE-2018-2628 KEV EXP | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… | Patch first | 9.8 critical | 100% | 2018-04-19 |
| CVE-2022-1388 KEV EXP | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5,… | Patch first | 9.8 critical | 100% | 2022-05-05 |
| CVE-2018-15961 KEV EXP | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerab… | Patch first | 9.8 critical | 100% | 2018-09-25 |
| CVE-2018-10562 KEV EXP | An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponFor… | Patch first | 9.8 critical | 99.9% | 2018-05-04 |
| CVE-2015-3113 KEV EXP | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468… | Patch first | 9.8 critical | 99.9% | 2015-06-23 |
| CVE-2022-30525 KEV EXP | A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware ve… | Patch first | 9.8 critical | 99.9% | 2022-05-12 |
| CVE-2021-3129 KEV EXP | Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure us… | Patch first | 9.8 critical | 99.9% | 2021-01-12 |
| CVE-2020-10189 KEV EXP | Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the Fi… | Patch first | 9.8 critical | 99.9% | 2020-03-06 |
| CVE-2014-7169 KEV EXP | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which… | Patch first | 9.8 critical | 99.9% | 2014-09-25 |
| CVE-2022-22963 KEV EXP | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a… | Patch first | 9.8 critical | 99.9% | 2022-04-01 |
| CVE-2024-27198 KEV EXP | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible | Patch first | 9.8 critical | 99.9% | 2024-03-04 |
| CVE-2025-24813 KEV EXP | Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded… | Patch first | 9.8 critical | 99.9% | 2025-03-10 |
| CVE-2024-32113 KEV EXP | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 1… | Patch first | 9.8 critical | 99.9% | 2024-05-08 |
| CVE-2019-3396 KEV EXP | The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the f… | Patch first | 9.8 critical | 99.9% | 2019-03-25 |
| CVE-2019-0604 KEV EXP | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka… | Patch first | 9.8 critical | 99.9% | 2019-03-05 |
| CVE-2015-1427 KEV EXP | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism an… | Patch first | 9.8 critical | 99.9% | 2015-02-17 |
| CVE-2020-7961 KEV EXP | Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSO… | Patch first | 9.8 critical | 99.9% | 2020-03-20 |
| CVE-2021-22986 KEV EXP | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ… | Patch first | 9.8 critical | 99.9% | 2021-03-31 |
| CVE-2014-0497 KEV EXP | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.33… | Patch first | 9.8 critical | 99.9% | 2014-02-05 |
| CVE-2022-35914 KEV EXP | /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection. | Patch first | 9.8 critical | 99.9% | 2022-09-19 |
| CVE-2021-36260 KEV EXP | A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vuln… | Patch first | 9.8 critical | 99.9% | 2021-09-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt