CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,502 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
36,453 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-44077 KEV | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthentica… | Patch first | 9.8 critical | 93.3% | 2021-11-29 |
| CVE-2020-2551 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected… | Patch first | 9.8 critical | 93.2% | 2020-01-15 |
| CVE-2021-40870 KEV | An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows… | Patch first | 9.8 critical | 93% | 2021-09-13 |
| CVE-2024-6670 KEV | In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted pa… | Patch first | 9.8 critical | 93% | 2024-08-29 |
| CVE-2016-3427 KEV | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confid… | Patch first | 9.8 critical | 92.3% | 2016-04-21 |
| CVE-2022-26258 KEV | D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp. | Patch first | 9.8 critical | 92% | 2022-03-28 |
| CVE-2020-10148 KEV | The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability coul… | Patch first | 9.8 critical | 92% | 2020-12-29 |
| CVE-2022-37042 KEV | Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing auth… | Patch first | 9.8 critical | 91.9% | 2022-08-12 |
| CVE-2024-11680 KEV | ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw… | Patch first | 9.8 critical | 91.7% | 2024-11-26 |
| CVE-2022-26352 KEV | An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose file… | Patch first | 9.8 critical | 91.6% | 2022-07-17 |
| CVE-2026-20182 KEV | May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed i… | Patch first | 10.0 critical | 91.5% | 2026-05-14 |
| CVE-2026-85706 KEV | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 1… | Patch first | 10.0 critical | 91.4% | 2026-09-12 |
| CVE-2025-9242 KEV | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code.… | Patch first | 9.8 critical | 91.3% | 2025-09-17 |
| CVE-2024-13160 KEV | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthent… | Patch first | 9.8 critical | 91.2% | 2025-01-14 |
| CVE-2021-35211 KEV | Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If e… | Patch first | 9.0 critical | 91.2% | 2021-07-14 |
| CVE-2026-1731 KEV | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code executi… | Patch first | 9.8 critical | 91% | 2026-02-06 |
| CVE-2017-12149 KEV | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFi… | Patch first | 9.8 critical | 90.7% | 2017-10-04 |
| CVE-2024-40711 KEV | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). | Patch first | 9.8 critical | 90.4% | 2024-09-07 |
| CVE-2016-8735 KEV | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12… | Patch first | 9.8 critical | 90.3% | 2017-04-06 |
| CVE-2025-37164 KEV | A remote code execution issue exists in HPE OneView. | Patch first | 10.0 critical | 90.2% | 2025-12-16 |
| CVE-2020-29583 KEV | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can b… | Patch first | 9.8 critical | 90.2% | 2020-12-22 |
| CVE-2023-40044 KEV | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Tra… | Patch first | 10.0 critical | 90.2% | 2023-09-27 |
| CVE-2024-13161 KEV | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthent… | Patch first | 9.8 critical | 90.1% | 2025-01-14 |
| CVE-2020-17463 KEV | FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. | Patch first | 9.8 critical | 89.7% | 2020-08-13 |
| CVE-2019-7195 KEV | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP reco… | Patch first | 9.8 critical | 89.7% | 2019-12-05 |
| CVE-2019-17621 KEV | The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system… | Patch first | 9.8 critical | 89.6% | 2019-12-30 |
| CVE-2025-26399 KEV | SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if expl… | Patch first | 9.8 critical | 89.5% | 2025-09-23 |
| CVE-2018-14839 KEV | LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with pa… | Patch first | 9.8 critical | 89.4% | 2019-05-14 |
| CVE-2021-20021 KEV | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP requ… | Patch first | 9.8 critical | 88.7% | 2021-04-09 |
| CVE-2025-61757 KEV | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.… | Patch first | 9.8 critical | 88.6% | 2025-10-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt