CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,529 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,726 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-22502 KEV | Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploi… | Patch first | 9.8 critical | 96.7% | 2021-02-08 |
| CVE-2020-1350 KEV | A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server… | Patch first | 10.0 critical | 96.7% | 2020-07-14 |
| CVE-2015-1641 KEV | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Autom… | Patch first | 7.8 high | 96.7% | 2015-04-14 |
| CVE-2018-6530 KEV | OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions,… | Patch first | 9.8 critical | 96.7% | 2018-03-06 |
| CVE-2024-57727 KEV | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attac… | Patch first | 7.5 high | 96.6% | 2025-01-15 |
| CVE-2023-33246 KEV | For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, includ… | Patch first | 9.8 critical | 96.6% | 2023-05-24 |
| CVE-2026-23760 KEV | SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-passwo… | Patch first | 9.8 critical | 96.5% | 2026-01-22 |
| CVE-2023-46747 KEV | Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the manage… | Patch first | 9.8 critical | 96.5% | 2023-10-26 |
| CVE-2020-8260 KEV | A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution u… | Patch first | 7.2 high | 96.5% | 2020-10-28 |
| CVE-2026-0257 KEV | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass sec… | Patch first | 9.1 critical | 96.4% | 2026-05-13 |
| CVE-2021-20124 KEV | A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthe… | Patch first | 7.5 high | 96.3% | 2021-10-13 |
| CVE-2021-35587 KEV | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11… | Patch first | 9.8 critical | 96.3% | 2022-01-19 |
| CVE-2017-3506 KEV | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected a… | Patch first | 7.4 high | 96.3% | 2017-04-24 |
| CVE-2020-17530 KEV | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0… | Patch first | 9.8 critical | 95.9% | 2020-12-11 |
| CVE-2025-61884 KEV | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-… | Patch first | 7.5 high | 95.9% | 2025-10-12 |
| CVE-2021-26857 KEV | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch first | 7.8 high | 95.8% | 2021-03-03 |
| CVE-2022-23131 KEV | In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user… | Patch first | 9.1 critical | 95.7% | 2022-01-13 |
| CVE-2020-5410 KEV | Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrar… | Patch first | 7.5 high | 95.6% | 2020-06-02 |
| CVE-2022-41352 KEV | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extra… | Patch first | 9.8 critical | 95.5% | 2022-09-26 |
| CVE-2024-1708 KEV | ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote c… | Patch first | 8.4 high | 95.4% | 2024-02-21 |
| CVE-2025-12480 KEV | Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after set… | Patch first | 9.1 critical | 95.4% | 2025-11-10 |
| CVE-2022-36537 KEV | ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the com… | Patch first | 7.5 high | 95.4% | 2022-08-26 |
| CVE-2024-1212 KEV | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. | Patch first | 10.0 critical | 95.4% | 2024-02-21 |
| CVE-2019-11580 KEV | Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthentica… | Patch first | 9.8 critical | 95.4% | 2019-06-03 |
| CVE-2019-7609 KEV | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion a… | Patch first | 10.0 critical | 95.3% | 2019-03-25 |
| CVE-2022-23134 KEV | After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Ma… | Patch first | 3.7 low | 95.3% | 2022-01-13 |
| CVE-2024-53704 KEV | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. | Patch first | 9.8 critical | 95.1% | 2025-01-09 |
| CVE-2018-0798 KEV | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulne… | Patch first | 8.8 high | 95.1% | 2018-01-10 |
| CVE-2017-12637 KEV | Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote at… | Patch first | 7.5 high | 95.1% | 2017-08-07 |
| CVE-2019-10068 KEV | An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate… | Patch first | 9.8 critical | 95.1% | 2019-03-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt