CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,514 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
615 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-21762 KEV | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through… | Patch first | 9.8 critical | 83.4% | 2024-02-09 |
| CVE-2019-7194 KEV | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP reco… | Patch first | 9.8 critical | 83.1% | 2019-12-05 |
| CVE-2020-3992 KEV | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-… | Patch first | 9.8 critical | 83% | 2020-10-20 |
| CVE-2024-42009 KEV | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim… | Patch first | 9.3 critical | 82.9% | 2024-08-05 |
| CVE-2021-27561 KEV | Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication. | Patch first | 9.8 critical | 82.9% | 2021-10-15 |
| CVE-2023-27992 KEV | The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior… | Patch first | 9.8 critical | 82.8% | 2023-06-19 |
| CVE-2023-43208 KEV | NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused b… | Patch first | 9.8 critical | 82.7% | 2023-10-26 |
| CVE-2014-1776 KEV | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of servic… | Patch first | 9.8 critical | 82.7% | 2014-04-27 |
| CVE-2024-43468 KEV | Microsoft Configuration Manager Remote Code Execution Vulnerability | Patch first | 9.8 critical | 80.9% | 2024-10-08 |
| CVE-2020-10987 KEV | The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceN… | Patch first | 9.8 critical | 79.8% | 2020-07-13 |
| CVE-2023-49103 KEV | An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.p… | Patch first | 10.0 critical | 78.4% | 2023-11-21 |
| CVE-2021-28799 KEV | An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allo… | Patch first | 10.0 critical | 78.3% | 2021-05-13 |
| CVE-2022-26318 KEV | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS be… | Patch first | 9.8 critical | 78.2% | 2022-03-04 |
| CVE-2026-16232 KEV | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicatio… | Patch first | 9.8 critical | 78% | 2026-07-22 |
| CVE-2026-8037 KEV | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary comm… | Patch first | 9.6 critical | 77.4% | 2026-06-04 |
| CVE-2023-34192 KEV | Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the… | Patch first | 9.0 critical | 77.3% | 2023-07-06 |
| CVE-2019-7238 KEV | Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control. | Patch first | 9.8 critical | 77.1% | 2019-03-21 |
| CVE-2026-25089 KEV | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.… | Patch first | 9.8 critical | 76.1% | 2026-06-09 |
| CVE-2025-1316 KEV | Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device | Patch first | 9.8 critical | 74.5% | 2025-03-05 |
| CVE-2021-42258 KEV | BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in… | Patch first | 9.8 critical | 74.4% | 2021-10-22 |
| CVE-2018-14667 KEV | The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated… | Patch first | 9.8 critical | 74.2% | 2018-11-06 |
| CVE-2017-8543 KEV | Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Wi… | Patch first | 9.8 critical | 74.2% | 2017-06-15 |
| CVE-2019-1003029 KEV | A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox… | Patch first | 9.9 critical | 73.9% | 2019-03-08 |
| CVE-2025-6205 KEV | A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access… | Patch first | 9.1 critical | 73.3% | 2025-08-04 |
| CVE-2025-2746 KEV | An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 u… | Patch first | 9.8 critical | 73% | 2025-03-24 |
| CVE-2022-20699 KEV | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch first | 10.0 critical | 72.5% | 2022-02-10 |
| CVE-2026-21962 KEV | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Pl… | Patch first | 10.0 critical | 70.9% | 2026-01-20 |
| CVE-2025-20333 KEV | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FT… | Patch first | 9.9 critical | 70.7% | 2025-09-25 |
| CVE-2020-4427 KEV | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with… | Patch first | 9.8 critical | 70% | 2020-05-07 |
| CVE-2021-44026 KEV | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. | Patch first | 9.8 critical | 69.9% | 2021-11-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt