CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,514 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
615 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-59718 KEV | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 t… | Patch first | 9.8 critical | 68.3% | 2025-12-09 |
| CVE-2023-28461 KEV | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gate… | Patch first | 9.8 critical | 68.1% | 2023-03-15 |
| CVE-2025-20337 KEV | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the unde… | Patch first | 10.0 critical | 67.8% | 2025-07-16 |
| CVE-2024-57726 KEV | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive perm… | Patch first | 9.9 critical | 66.6% | 2025-01-15 |
| CVE-2025-2776 KEV | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functiona… | Patch first | 9.3 critical | 64.4% | 2025-05-07 |
| CVE-2016-20017 KEV | D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016… | Patch first | 9.8 critical | 64.2% | 2022-10-19 |
| CVE-2015-4068 KEV | Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of ser… | Patch first | 9.1 critical | 63.6% | 2015-05-29 |
| CVE-2021-22681 KEV | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers ar… | Patch first | 9.8 critical | 63.6% | 2021-03-03 |
| CVE-2022-21445 KEV | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions th… | Patch first | 9.8 critical | 62.5% | 2022-04-19 |
| CVE-2024-23113 KEV | A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy v… | Patch first | 9.8 critical | 61.7% | 2024-02-15 |
| CVE-2020-4428 KEV | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Fo… | Patch first | 9.1 critical | 61.7% | 2020-05-07 |
| CVE-2018-4939 KEV | Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vul… | Patch first | 9.8 critical | 61.7% | 2018-05-19 |
| CVE-2015-7755 KEV | Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b… | Patch first | 9.8 critical | 61.1% | 2015-12-19 |
| CVE-2021-22991 KEV | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclos… | Patch first | 9.8 critical | 61.1% | 2021-03-31 |
| CVE-2024-54085 KEV | AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful ex… | Patch first | 9.8 critical | 60.7% | 2025-03-11 |
| CVE-2024-8956 KEV | PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authenti… | Patch first | 9.1 critical | 58.8% | 2024-09-17 |
| CVE-2020-26919 KEV | NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level. | Patch first | 9.8 critical | 57.5% | 2020-10-09 |
| CVE-2021-27104 KEV | Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA… | Patch first | 9.8 critical | 56.7% | 2021-02-16 |
| CVE-2019-19006 KEV | Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. | Patch first | 9.8 critical | 55.9% | 2019-11-21 |
| CVE-2022-37055 KEV | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main, | Patch first | 9.8 critical | 55.5% | 2022-08-28 |
| CVE-2018-0125 KEV | A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated… | Patch first | 9.8 critical | 55.2% | 2018-02-08 |
| CVE-2024-38812 KEV | The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCent… | Patch first | 9.8 critical | 54.6% | 2024-09-17 |
| CVE-2020-29557 KEV | An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achie… | Patch first | 9.8 critical | 54.3% | 2021-01-29 |
| CVE-2022-29499 KEV | The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Servi… | Patch first | 9.8 critical | 54.3% | 2022-04-26 |
| CVE-2021-22941 KEV | Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the s… | Patch first | 9.8 critical | 53.6% | 2021-09-23 |
| CVE-2025-14611 KEV | Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degra… | Patch first | 9.8 critical | 53.3% | 2025-12-12 |
| CVE-2023-45249 KEV | Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-6… | Patch first | 9.8 critical | 53.3% | 2024-07-24 |
| CVE-2025-53690 KEV | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issu… | Patch first | 9.0 critical | 51.1% | 2025-09-03 |
| CVE-2020-12812 KEV | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succes… | Patch first | 9.8 critical | 49.3% | 2020-07-24 |
| CVE-2011-1889 KEV | The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitra… | Patch first | 9.8 critical | 49% | 2011-06-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt