CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,558 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,726 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-33053 KEV | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | Patch first | 8.8 high | 87% | 2025-06-10 |
| CVE-2021-31755 KEV | An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows at… | Patch first | 9.8 critical | 86.9% | 2021-05-07 |
| CVE-2017-18362 KEV | ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to th… | Patch first | 9.8 critical | 86.8% | 2019-02-05 |
| CVE-2021-40655 KEV | An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a pos… | Patch first | 7.5 high | 86.7% | 2021-09-24 |
| CVE-2024-51567 KEV | upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute a… | Patch first | 10.0 critical | 86.6% | 2024-10-29 |
| CVE-2025-4428 KEV | Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to… | Patch first | 7.2 high | 86.5% | 2025-05-13 |
| CVE-2019-16057 KEV | The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection. | Patch first | 9.8 critical | 86.5% | 2019-09-16 |
| CVE-2021-21017 KEV | Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap… | Patch first | 8.8 high | 86.3% | 2021-02-11 |
| CVE-2015-2545 KEV | Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microso… | Patch first | 7.8 high | 85.9% | 2015-09-09 |
| CVE-2026-24858 KEV | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Forti… | Patch first | 9.8 critical | 85.8% | 2026-01-27 |
| CVE-2021-30116 KEV | Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page w… | Patch first | 10.0 critical | 85.7% | 2021-07-09 |
| CVE-2023-27997 KEV | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6… | Patch first | 9.8 critical | 85.7% | 2023-06-13 |
| CVE-2025-52691 KEV | Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, pot… | Patch first | 10.0 critical | 85.7% | 2025-12-29 |
| CVE-2020-3580 KEV | Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) So… | Patch first | 6.1 medium | 85.6% | 2020-10-21 |
| CVE-2022-27924 KEV | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These… | Patch first | 7.5 high | 85.4% | 2022-04-21 |
| CVE-2023-24955 KEV | Microsoft SharePoint Server Remote Code Execution Vulnerability | Patch first | 7.2 high | 85.4% | 2023-05-09 |
| CVE-2021-1675 KEV | Windows Print Spooler Remote Code Execution Vulnerability | Patch first | 7.8 high | 85.3% | 2021-06-08 |
| CVE-2025-8110 KEV | Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. | Patch first | 8.8 high | 85.2% | 2025-12-10 |
| CVE-2023-41266 KEV | A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier… | Patch first | 8.2 high | 84.8% | 2023-08-29 |
| CVE-2019-10758 KEV | mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to per… | Patch first | 9.9 critical | 84.7% | 2019-12-24 |
| CVE-2024-28986 KEV | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an… | Patch first | 9.8 critical | 84.6% | 2024-08-13 |
| CVE-2019-11581 KEV | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An… | Patch first | 9.8 critical | 84.6% | 2019-08-09 |
| CVE-2025-64328 KEV | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore… | Patch first | 7.2 high | 84.6% | 2025-11-07 |
| CVE-2020-28949 KEV | Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to ov… | Patch first | 7.8 high | 84.6% | 2020-11-19 |
| CVE-2020-15415 KEV | On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell m… | Patch first | 9.8 critical | 84.5% | 2020-06-30 |
| CVE-2020-7796 KEV | Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. | Patch first | 9.8 critical | 84.4% | 2020-02-18 |
| CVE-2020-12641 KEV | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for i… | Patch first | 9.8 critical | 84.3% | 2020-05-04 |
| CVE-2024-38112 KEV | Windows MSHTML Platform Spoofing Vulnerability | Patch first | 7.5 high | 84.2% | 2024-07-09 |
| CVE-2025-40551 KEV | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whic… | Patch first | 9.8 critical | 84.2% | 2026-01-28 |
| CVE-2021-21224 KEV | Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pa… | Patch first | 8.8 high | 84.2% | 2021-04-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt