CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,069 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,703 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-22524 | Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets… | Patch early | 9.8 critical | 24.5% | 2023-12-06 |
| CVE-2018-18949 | Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings. | Patch early | 9.8 critical | 24.5% | 2018-11-05 |
| CVE-2018-20173 | Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API. | Patch early | 9.8 critical | 24.5% | 2018-12-17 |
| CVE-2020-11989 | Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass. | Patch early | 9.8 critical | 24.4% | 2020-06-22 |
| CVE-2019-12525 | An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header… | Patch early | 9.8 critical | 24.4% | 2019-07-11 |
| CVE-2023-51123 | An issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted POST request to the service para… | Patch early | 9.8 critical | 24.4% | 2024-01-10 |
| CVE-2024-52046 | The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary… | Patch early | 9.8 critical | 24.4% | 2024-12-25 |
| CVE-2024-21899 | An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could all… | Patch early | 9.8 critical | 24.4% | 2024-03-08 |
| CVE-2019-19838 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=ge… | Patch early | 9.8 critical | 24.4% | 2020-01-23 |
| CVE-2022-31656 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A m… | Patch early | 9.8 critical | 24.3% | 2022-08-05 |
| CVE-2025-8868 | In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricte… | Patch early | 9.8 critical | 24.3% | 2025-09-29 |
| CVE-2024-4884 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The Apm.UI.Areas.A… | Patch early | 9.8 critical | 24.3% | 2024-06-25 |
| CVE-2023-33299 | A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to exec… | Patch early | 9.8 critical | 24.3% | 2023-06-23 |
| CVE-2022-28021 | Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user. | Patch early | 9.8 critical | 24.3% | 2022-04-21 |
| CVE-2025-25279 | Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing board… | Patch early | 9.9 critical | 24.2% | 2025-02-24 |
| CVE-2021-44757 | Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sen… | Patch early | 9.1 critical | 24.2% | 2022-01-18 |
| CVE-2017-8303 | An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the… | Patch early | 9.8 critical | 24.2% | 2017-05-05 |
| CVE-2023-34600 | Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. | Patch early | 9.8 critical | 24.2% | 2023-06-20 |
| CVE-2021-21809 | A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lea… | Patch early | 9.1 critical | 24.2% | 2021-06-23 |
| CVE-2018-17157 | In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a s… | Patch early | 9.8 critical | 24.2% | 2018-12-04 |
| CVE-2017-9544 | There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1. By sending an overly long us… | Patch early | 9.8 critical | 24.1% | 2017-06-12 |
| CVE-2018-1145 | A remote unauthenticated user can overflow a stack buffer in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to proxy… | Patch early | 9.8 critical | 24.1% | 2018-04-19 |
| CVE-2017-11386 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation… | Patch early | 9.8 critical | 24.1% | 2017-08-02 |
| CVE-2018-8154 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microso… | Patch early | 9.8 critical | 24.1% | 2018-05-09 |
| CVE-2013-7471 | An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 re… | Patch early | 9.8 critical | 24% | 2019-06-11 |
| CVE-2023-25135 | vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserializatio… | Patch early | 9.8 critical | 23.9% | 2023-02-03 |
| CVE-2022-33107 | ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Abstra… | Patch early | 9.8 critical | 23.9% | 2022-06-29 |
| CVE-2019-0189 | The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and u… | Patch early | 9.8 critical | 23.7% | 2019-09-11 |
| CVE-2022-22930 | A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafte… | Patch early | 9.8 critical | 23.7% | 2022-01-21 |
| CVE-2025-54574 | Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution atta… | Patch early | 9.3 critical | 23.7% | 2025-08-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt