CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,095 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
36,706 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-5824 | An unauthenticated remote code execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found. | Patch early | 9.8 critical | 19.3% | 2018-02-15 |
| CVE-2024-31750 | SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter. | Patch early | 9.8 critical | 19.3% | 2024-04-19 |
| CVE-2019-16340 | Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI. | Patch early | 9.8 critical | 19.3% | 2019-11-21 |
| CVE-2022-29006 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attacker… | Patch early | 9.8 critical | 19.3% | 2022-05-11 |
| CVE-2022-29007 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows at… | Patch early | 9.8 critical | 19.3% | 2022-05-11 |
| CVE-2020-11518 | Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution. | Patch early | 9.8 critical | 19.2% | 2020-04-04 |
| CVE-2024-32501 | A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x b… | Patch early | 9.8 critical | 19.2% | 2024-08-23 |
| CVE-2021-45427 | Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete f… | Patch early | 9.8 critical | 19.2% | 2021-12-30 |
| CVE-2016-3082 | XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary c… | Patch early | 9.8 critical | 19.2% | 2016-04-26 |
| CVE-2021-41403 | flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities. | Patch early | 9.8 critical | 19.1% | 2022-06-15 |
| CVE-2024-25850 | Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter | Patch early | 9.8 critical | 19.1% | 2024-02-22 |
| CVE-2025-56005 | An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the… | Patch early | 9.8 critical | 19.1% | 2026-01-20 |
| CVE-2023-44974 | An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading… | Patch early | 9.8 critical | 19.1% | 2023-10-03 |
| CVE-2018-12533 | JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java… | Patch early | 9.8 critical | 19% | 2018-06-18 |
| CVE-2024-6671 | In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an u… | Patch early | 9.8 critical | 19% | 2024-08-29 |
| CVE-2024-21894 | A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious use… | Patch early | 9.8 critical | 19% | 2024-04-04 |
| CVE-2022-37434 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only appli… | Patch early | 9.8 critical | 19% | 2022-08-05 |
| CVE-2022-3900 | The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_… | Patch early | 9.8 critical | 19% | 2022-12-12 |
| CVE-2023-38547 | A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configura… | Patch early | 9.8 critical | 18.9% | 2023-11-07 |
| CVE-2017-0028 | A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The vulnerability could corrupt me… | Patch early | 9.8 critical | 18.9% | 2017-07-17 |
| CVE-2018-8013 | In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name wh… | Patch early | 9.8 critical | 18.9% | 2018-05-24 |
| CVE-2022-43634 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit… | Patch early | 9.8 critical | 18.9% | 2023-03-29 |
| CVE-2017-9800 | A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run a… | Patch early | 9.8 critical | 18.9% | 2017-08-11 |
| CVE-2024-38666 | An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specia… | Patch early | 9.1 critical | 18.9% | 2025-01-14 |
| CVE-2020-11898 | The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger… | Patch early | 9.1 critical | 18.9% | 2020-06-17 |
| CVE-2019-8074 | ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Successful exploitation could le… | Patch early | 9.8 critical | 18.9% | 2019-09-27 |
| CVE-2022-38129 | A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management… | Patch early | 9.8 critical | 18.9% | 2022-08-10 |
| CVE-2023-23368 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow… | Patch early | 9.8 critical | 18.8% | 2023-11-03 |
| CVE-2019-14271 | In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a… | Patch early | 9.8 critical | 18.8% | 2019-07-29 |
| CVE-2023-22457 | CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a p… | Patch early | 9.0 critical | 18.7% | 2023-01-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt