CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,553 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,726 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-3427 KEV | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confid… | Patch first | 9.8 critical | 92.3% | 2016-04-21 |
| CVE-2025-11371 KEV | In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows u… | Patch first | 7.5 high | 92.1% | 2025-10-09 |
| CVE-2022-26258 KEV | D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp. | Patch first | 9.8 critical | 92% | 2022-03-28 |
| CVE-2020-10148 KEV | The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability coul… | Patch first | 9.8 critical | 92% | 2020-12-29 |
| CVE-2024-7399 KEV | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to wri… | Patch first | 8.8 high | 91.9% | 2024-08-12 |
| CVE-2022-37042 KEV | Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing auth… | Patch first | 9.8 critical | 91.9% | 2022-08-12 |
| CVE-2021-42321 KEV | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch first | 8.8 high | 91.7% | 2021-11-10 |
| CVE-2024-11680 KEV | ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw… | Patch first | 9.8 critical | 91.7% | 2024-11-26 |
| CVE-2022-26352 KEV | An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose file… | Patch first | 9.8 critical | 91.6% | 2022-07-17 |
| CVE-2026-20182 KEV | May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed i… | Patch first | 10.0 critical | 91.5% | 2026-05-14 |
| CVE-2026-85706 KEV | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 1… | Patch first | 10.0 critical | 91.4% | 2026-09-12 |
| CVE-2025-9242 KEV | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code.… | Patch first | 9.8 critical | 91.3% | 2025-09-17 |
| CVE-2024-13160 KEV | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthent… | Patch first | 9.8 critical | 91.2% | 2025-01-14 |
| CVE-2021-35211 KEV | Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If e… | Patch first | 9.0 critical | 91.2% | 2021-07-14 |
| CVE-2026-1731 KEV | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code executi… | Patch first | 9.8 critical | 91% | 2026-02-06 |
| CVE-2020-8243 KEV | A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform a… | Patch first | 7.2 high | 90.8% | 2020-09-30 |
| CVE-2017-12149 KEV | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFi… | Patch first | 9.8 critical | 90.7% | 2017-10-04 |
| CVE-2021-21315 KEV | The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,… | Patch first | 7.1 high | 90.7% | 2021-02-16 |
| CVE-2025-6218 KEV | RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… | Patch first | 7.8 high | 90.5% | 2025-06-21 |
| CVE-2021-32648 KEV | octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account… | Patch first | 8.2 high | 90.4% | 2021-08-26 |
| CVE-2024-40711 KEV | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). | Patch first | 9.8 critical | 90.4% | 2024-09-07 |
| CVE-2023-41763 KEV | Skype for Business Elevation of Privilege Vulnerability | Patch first | 5.3 medium | 90.4% | 2023-10-10 |
| CVE-2016-8735 KEV | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12… | Patch first | 9.8 critical | 90.3% | 2017-04-06 |
| CVE-2021-20123 KEV | A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. A… | Patch first | 7.5 high | 90.2% | 2021-10-13 |
| CVE-2025-37164 KEV | A remote code execution issue exists in HPE OneView. | Patch first | 10.0 critical | 90.2% | 2025-12-16 |
| CVE-2020-29583 KEV | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can b… | Patch first | 9.8 critical | 90.2% | 2020-12-22 |
| CVE-2023-40044 KEV | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Tra… | Patch first | 10.0 critical | 90.2% | 2023-09-27 |
| CVE-2024-13161 KEV | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthent… | Patch first | 9.8 critical | 90.1% | 2025-01-14 |
| CVE-2023-36844 KEV | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacke… | Patch first | 5.3 medium | 90% | 2023-08-17 |
| CVE-2020-17463 KEV | FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. | Patch first | 9.8 critical | 89.7% | 2020-08-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt