CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,503 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,455 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-6530 KEV | OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions,… | Patch first | 9.8 critical | 96.7% | 2018-03-06 |
| CVE-2023-33246 KEV | For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, includ… | Patch first | 9.8 critical | 96.6% | 2023-05-24 |
| CVE-2026-23760 KEV | SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-passwo… | Patch first | 9.8 critical | 96.5% | 2026-01-22 |
| CVE-2023-46747 KEV | Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the manage… | Patch first | 9.8 critical | 96.5% | 2023-10-26 |
| CVE-2026-0257 KEV | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass sec… | Patch first | 9.1 critical | 96.4% | 2026-05-13 |
| CVE-2021-35587 KEV | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11… | Patch first | 9.8 critical | 96.3% | 2022-01-19 |
| CVE-2020-17530 KEV | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0… | Patch first | 9.8 critical | 95.9% | 2020-12-11 |
| CVE-2022-23131 KEV | In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user… | Patch first | 9.1 critical | 95.7% | 2022-01-13 |
| CVE-2022-41352 KEV | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extra… | Patch first | 9.8 critical | 95.5% | 2022-09-26 |
| CVE-2025-12480 KEV | Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after set… | Patch first | 9.1 critical | 95.4% | 2025-11-10 |
| CVE-2024-1212 KEV | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. | Patch first | 10.0 critical | 95.4% | 2024-02-21 |
| CVE-2019-11580 KEV | Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthentica… | Patch first | 9.8 critical | 95.4% | 2019-06-03 |
| CVE-2019-7609 KEV | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion a… | Patch first | 10.0 critical | 95.3% | 2019-03-25 |
| CVE-2024-53704 KEV | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. | Patch first | 9.8 critical | 95.1% | 2025-01-09 |
| CVE-2019-10068 KEV | An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate… | Patch first | 9.8 critical | 95.1% | 2019-03-26 |
| CVE-2023-36845 KEV | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, ne… | Patch first | 9.8 critical | 95.1% | 2023-08-17 |
| CVE-2020-2883 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0… | Patch first | 9.8 critical | 94.9% | 2020-04-15 |
| CVE-2025-54309 KEV | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote at… | Patch first | 9.0 critical | 94.9% | 2025-07-18 |
| CVE-2024-47575 KEV | A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager… | Patch first | 9.8 critical | 94.8% | 2024-10-23 |
| CVE-2020-6287 KEV | SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker… | Patch first | 10.0 critical | 94.7% | 2020-07-14 |
| CVE-2024-21413 KEV | Microsoft Outlook Remote Code Execution Vulnerability | Patch first | 9.8 critical | 94.7% | 2024-02-13 |
| CVE-2020-14644 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0… | Patch first | 9.8 critical | 94.5% | 2020-07-15 |
| CVE-2025-54236 KEV | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vul… | Patch first | 9.1 critical | 94.5% | 2025-09-09 |
| CVE-2017-18368 KEV | The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remot… | Patch first | 9.8 critical | 94.4% | 2019-05-02 |
| CVE-2025-30406 KEV | Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcode… | Patch first | 9.0 critical | 94.3% | 2025-04-03 |
| CVE-2024-55591 KEV | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy vers… | Patch first | 9.8 critical | 94.1% | 2025-01-14 |
| CVE-2025-11953 KEV | The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoi… | Patch first | 9.8 critical | 94% | 2025-11-03 |
| CVE-2024-55956 KEV | In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash… | Patch first | 9.8 critical | 94% | 2024-12-13 |
| CVE-2025-24016 KEV | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an… | Patch first | 9.9 critical | 93.8% | 2025-02-10 |
| CVE-2026-21643 KEV | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an un… | Patch first | 9.8 critical | 93.7% | 2026-02-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt