CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,514 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,455 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-10758 KEV | mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to per… | Patch first | 9.9 critical | 84.7% | 2019-12-24 |
| CVE-2024-28986 KEV | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an… | Patch first | 9.8 critical | 84.6% | 2024-08-13 |
| CVE-2019-11581 KEV | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An… | Patch first | 9.8 critical | 84.6% | 2019-08-09 |
| CVE-2020-15415 KEV | On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell m… | Patch first | 9.8 critical | 84.5% | 2020-06-30 |
| CVE-2020-7796 KEV | Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. | Patch first | 9.8 critical | 84.4% | 2020-02-18 |
| CVE-2020-12641 KEV | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for i… | Patch first | 9.8 critical | 84.3% | 2020-05-04 |
| CVE-2025-40551 KEV | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whic… | Patch first | 9.8 critical | 84.2% | 2026-01-28 |
| CVE-2024-43451 KEV | NTLM Hash Disclosure Spoofing Vulnerability | Patch first | 6.5 medium | 84.1% | 2024-11-12 |
| CVE-2019-9874 KEV | Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allow… | Patch first | 9.8 critical | 83.7% | 2019-05-31 |
| CVE-2023-36847 KEV | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attack… | Patch first | 5.3 medium | 83.5% | 2023-08-17 |
| CVE-2024-21762 KEV | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through… | Patch first | 9.8 critical | 83.4% | 2024-02-09 |
| CVE-2019-7194 KEV | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP reco… | Patch first | 9.8 critical | 83.1% | 2019-12-05 |
| CVE-2020-3992 KEV | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-… | Patch first | 9.8 critical | 83% | 2020-10-20 |
| CVE-2024-42009 KEV | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim… | Patch first | 9.3 critical | 82.9% | 2024-08-05 |
| CVE-2021-27561 KEV | Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication. | Patch first | 9.8 critical | 82.9% | 2021-10-15 |
| CVE-2023-27992 KEV | The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior… | Patch first | 9.8 critical | 82.8% | 2023-06-19 |
| CVE-2024-0769 KEV | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unk… | Patch first | 5.3 medium | 82.7% | 2024-01-21 |
| CVE-2023-43208 KEV | NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused b… | Patch first | 9.8 critical | 82.7% | 2023-10-26 |
| CVE-2014-1776 KEV | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of servic… | Patch first | 9.8 critical | 82.7% | 2014-04-27 |
| CVE-2021-31955 KEV | Windows Kernel Information Disclosure Vulnerability | Patch first | 5.5 medium | 81.1% | 2021-06-08 |
| CVE-2024-43468 KEV | Microsoft Configuration Manager Remote Code Execution Vulnerability | Patch first | 9.8 critical | 80.9% | 2024-10-08 |
| CVE-2020-10987 KEV | The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceN… | Patch first | 9.8 critical | 79.8% | 2020-07-13 |
| CVE-2018-18809 KEV | The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperRep… | Patch first | 6.5 medium | 79.1% | 2019-03-07 |
| CVE-2023-49103 KEV | An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.p… | Patch first | 10.0 critical | 78.4% | 2023-11-21 |
| CVE-2021-28799 KEV | An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allo… | Patch first | 10.0 critical | 78.3% | 2021-05-13 |
| CVE-2022-26318 KEV | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS be… | Patch first | 9.8 critical | 78.2% | 2022-03-04 |
| CVE-2023-24880 KEV | Windows SmartScreen Security Feature Bypass Vulnerability | Patch first | 4.4 medium | 78% | 2023-03-14 |
| CVE-2026-16232 KEV | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicatio… | Patch first | 9.8 critical | 78% | 2026-07-22 |
| CVE-2026-8037 KEV | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary comm… | Patch first | 9.6 critical | 77.4% | 2026-06-04 |
| CVE-2023-34192 KEV | Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the… | Patch first | 9.0 critical | 77.3% | 2023-07-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt