CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,503 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
36,454 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-48908 KEV | A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution… | Patch first | 9.8 critical | 88.5% | 2026-06-20 |
| CVE-2026-20127 KEV | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-… | Patch first | 10.0 critical | 88.5% | 2026-02-25 |
| CVE-2023-41265 KEV | An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 an… | Patch first | 9.6 critical | 88.2% | 2023-08-29 |
| CVE-2026-20079 KEV | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypa… | Patch first | 10.0 critical | 88.2% | 2026-03-04 |
| CVE-2026-24423 KEV | SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. T… | Patch first | 9.8 critical | 88.2% | 2026-01-23 |
| CVE-2019-7192 KEV | This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recom… | Patch first | 9.8 critical | 88.1% | 2019-12-05 |
| CVE-2025-54253 KEV | Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. A… | Patch first | 10.0 critical | 88% | 2025-08-05 |
| CVE-2022-27593 KEV | An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could al… | Patch first | 10.0 critical | 87.9% | 2022-09-08 |
| CVE-2024-58136 KEV | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild… | Patch first | 9.0 critical | 87.8% | 2025-04-10 |
| CVE-2020-17496 KEV | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.… | Patch first | 9.8 critical | 87.7% | 2020-08-12 |
| CVE-2023-2868 KEV | A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.… | Patch first | 9.4 critical | 87.7% | 2023-05-24 |
| CVE-2026-71362 KEV | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vuln… | Patch first | 9.1 critical | 87.5% | 2026-08-11 |
| CVE-2022-26143 KEV | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain se… | Patch first | 9.8 critical | 87.3% | 2022-03-10 |
| CVE-2024-12356 KEV | A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated att… | Patch first | 9.8 critical | 87.3% | 2024-12-17 |
| CVE-2021-31755 KEV | An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows at… | Patch first | 9.8 critical | 86.9% | 2021-05-07 |
| CVE-2017-18362 KEV | ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to th… | Patch first | 9.8 critical | 86.8% | 2019-02-05 |
| CVE-2024-51567 KEV | upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute a… | Patch first | 10.0 critical | 86.6% | 2024-10-29 |
| CVE-2019-16057 KEV | The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection. | Patch first | 9.8 critical | 86.5% | 2019-09-16 |
| CVE-2026-24858 KEV | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Forti… | Patch first | 9.8 critical | 85.8% | 2026-01-27 |
| CVE-2021-30116 KEV | Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page w… | Patch first | 10.0 critical | 85.7% | 2021-07-09 |
| CVE-2023-27997 KEV | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6… | Patch first | 9.8 critical | 85.7% | 2023-06-13 |
| CVE-2025-52691 KEV | Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, pot… | Patch first | 10.0 critical | 85.7% | 2025-12-29 |
| CVE-2019-10758 KEV | mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to per… | Patch first | 9.9 critical | 84.7% | 2019-12-24 |
| CVE-2024-28986 KEV | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an… | Patch first | 9.8 critical | 84.6% | 2024-08-13 |
| CVE-2019-11581 KEV | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An… | Patch first | 9.8 critical | 84.6% | 2019-08-09 |
| CVE-2020-15415 KEV | On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell m… | Patch first | 9.8 critical | 84.5% | 2020-06-30 |
| CVE-2020-7796 KEV | Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. | Patch first | 9.8 critical | 84.4% | 2020-02-18 |
| CVE-2020-12641 KEV | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for i… | Patch first | 9.8 critical | 84.3% | 2020-05-04 |
| CVE-2025-40551 KEV | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whic… | Patch first | 9.8 critical | 84.2% | 2026-01-28 |
| CVE-2019-9874 KEV | Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allow… | Patch first | 9.8 critical | 83.7% | 2019-05-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt