CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,502 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
615 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-20887 KEV | Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks… | Patch first | 9.8 critical | 98.3% | 2023-06-07 |
| CVE-2022-26138 KEV | The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with… | Patch first | 9.8 critical | 98.2% | 2022-07-20 |
| CVE-2020-6207 KEV | SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service… | Patch first | 9.8 critical | 98.1% | 2020-03-10 |
| CVE-2024-41713 KEV | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated atta… | Patch first | 9.1 critical | 98.1% | 2024-10-21 |
| CVE-2023-25717 KEV | Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_use… | Patch first | 9.8 critical | 98.1% | 2023-02-13 |
| CVE-2024-3272 KEV | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-3… | Patch first | 9.8 critical | 98% | 2024-04-04 |
| CVE-2021-35395 KEV | Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access po… | Patch first | 9.8 critical | 98% | 2021-08-16 |
| CVE-2018-19410 KEV | PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator).… | Patch first | 9.8 critical | 97.9% | 2018-11-21 |
| CVE-2023-25280 KEV | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_ad… | Patch first | 9.8 critical | 97.9% | 2023-03-16 |
| CVE-2021-45382 KEV | A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L route… | Patch first | 9.8 critical | 97.8% | 2022-02-17 |
| CVE-2021-36380 KEV | Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi. | Patch first | 9.8 critical | 97.6% | 2021-08-13 |
| CVE-2025-20281 KEV | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the unde… | Patch first | 10.0 critical | 97.6% | 2025-06-25 |
| CVE-2021-42237 KEV | Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote… | Patch first | 9.8 critical | 97.6% | 2021-11-05 |
| CVE-2025-34028 KEV | The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expande… | Patch first | 10.0 critical | 97.6% | 2025-04-22 |
| CVE-2024-56145 KEV | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this… | Patch first | 9.8 critical | 97.4% | 2024-12-18 |
| CVE-2023-24489 KEV | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated att… | Patch first | 9.8 critical | 97.3% | 2023-07-10 |
| CVE-2019-5544 KEV | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Criti… | Patch first | 9.8 critical | 97.3% | 2019-12-06 |
| CVE-2021-41277 KEV | Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->set… | Patch first | 10.0 critical | 97.2% | 2021-11-17 |
| CVE-2025-2747 KEV | An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for t… | Patch first | 9.8 critical | 97.2% | 2025-03-24 |
| CVE-2023-23397 KEV | Microsoft Outlook Elevation of Privilege Vulnerability | Patch first | 9.8 critical | 97.2% | 2023-03-14 |
| CVE-2024-20439 KEV | A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a stat… | Patch first | 9.8 critical | 97.1% | 2024-09-04 |
| CVE-2023-38203 KEV | Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vul… | Patch first | 9.8 critical | 97.1% | 2023-07-20 |
| CVE-2025-54068 KEV | Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve… | Patch first | 9.8 critical | 97.1% | 2025-07-17 |
| CVE-2018-1273 KEV | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused b… | Patch first | 9.8 critical | 97% | 2018-04-11 |
| CVE-2026-20253 KEV | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through… | Patch first | 9.8 critical | 96.9% | 2026-06-10 |
| CVE-2025-5086 KEV | A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution… | Patch first | 9.0 critical | 96.9% | 2025-06-02 |
| CVE-2020-25223 KEV | A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11 | Patch first | 9.8 critical | 96.8% | 2020-09-25 |
| CVE-2021-22502 KEV | Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploi… | Patch first | 9.8 critical | 96.7% | 2021-02-08 |
| CVE-2020-1350 KEV | A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server… | Patch first | 10.0 critical | 96.7% | 2020-07-14 |
| CVE-2018-6530 KEV | OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions,… | Patch first | 9.8 critical | 96.7% | 2018-03-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt