CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,502 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
317,898 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-45195 KEV | Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade… | Patch first | 7.5 high | 100% | 2024-09-04 |
| CVE-2023-4863 KEV | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memor… | Patch first | 8.8 high | 100% | 2023-09-12 |
| CVE-2024-24919 KEV | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote A… | Patch first | 8.6 high | 100% | 2024-05-28 |
| CVE-2022-41082 KEV | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch first | 8.0 high | 100% | 2022-10-03 |
| CVE-2022-41040 KEV | Microsoft Exchange Server Elevation of Privilege Vulnerability | Patch first | 8.8 high | 100% | 2022-10-03 |
| CVE-2024-29824 KEV | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network… | Patch first | 8.8 high | 99.9% | 2024-05-31 |
| CVE-2019-7481 KEV | Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 ver… | Patch first | 7.5 high | 99.9% | 2019-12-17 |
| CVE-2023-21839 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.… | Patch first | 7.5 high | 99.9% | 2023-01-18 |
| CVE-2023-38831 KEV | RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs… | Patch first | 7.8 high | 99.8% | 2023-08-23 |
| CVE-2021-34527 KEV | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who su… | Patch first | 8.8 high | 99.8% | 2021-07-02 |
| CVE-2023-29298 KEV | Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vul… | Patch first | 7.5 high | 99.8% | 2023-07-12 |
| CVE-2021-31207 KEV | Microsoft Exchange Server Security Feature Bypass Vulnerability | Patch first | 6.6 medium | 99.8% | 2021-05-11 |
| CVE-2023-38205 KEV | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerabilit… | Patch first | 7.5 high | 99.7% | 2023-09-14 |
| CVE-2021-22054 KEV | VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 cont… | Patch first | 7.5 high | 99.7% | 2021-12-17 |
| CVE-2024-21412 KEV | Internet Shortcut Files Security Feature Bypass Vulnerability | Patch first | 8.1 high | 99.4% | 2024-02-13 |
| CVE-2022-30190 KEV | A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who succe… | Patch first | 7.8 high | 99.2% | 2022-06-01 |
| CVE-2022-30333 KEV | RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by c… | Patch first | 7.5 high | 99.1% | 2022-05-09 |
| CVE-2025-49706 KEV | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | Patch first | 6.5 medium | 99.1% | 2025-07-08 |
| CVE-2023-36884 KEV | Windows Search Remote Code Execution Vulnerability | Patch first | 7.5 high | 98.9% | 2023-07-11 |
| CVE-2022-27925 KEV | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated us… | Patch first | 7.2 high | 98.7% | 2022-04-21 |
| CVE-2024-29059 KEV | .NET Framework Information Disclosure Vulnerability | Patch first | 7.5 high | 98.6% | 2024-03-23 |
| CVE-2024-9463 KEV | An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expe… | Patch first | 7.5 high | 98.5% | 2024-10-09 |
| CVE-2021-21311 KEV | Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forg… | Patch first | 7.2 high | 98.5% | 2021-02-11 |
| CVE-2021-33766 KEV | Microsoft Exchange Server Information Disclosure Vulnerability | Patch first | 7.3 high | 98.1% | 2021-07-14 |
| CVE-2021-39144 KEV | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffic… | Patch first | 8.5 high | 98.1% | 2021-08-23 |
| CVE-2024-12987 KEV | A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /… | Patch first | 7.3 high | 98.1% | 2024-12-27 |
| CVE-2020-14883 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.… | Patch first | 7.2 high | 97.9% | 2020-10-21 |
| CVE-2020-25078 KEV | An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint all… | Patch first | 7.5 high | 97.5% | 2020-09-02 |
| CVE-2021-40444 KEV | Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted a… | Patch first | 8.8 high | 97.5% | 2021-09-15 |
| CVE-2023-26360 KEV | Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that c… | Patch first | 8.6 high | 97.3% | 2023-03-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt