CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,503 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
398,503 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-1498 KEV | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform comman… | Patch first | 9.8 critical | 100% | 2021-05-06 |
| CVE-2023-35082 KEV | An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of th… | Patch first | 9.8 critical | 100% | 2023-08-15 |
| CVE-2021-21985 KEV | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in whic… | Patch first | 9.8 critical | 100% | 2021-05-26 |
| CVE-2021-22005 KEV | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCen… | Patch first | 9.8 critical | 100% | 2021-09-23 |
| CVE-2023-22518 KEV | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an… | Patch first | 9.8 critical | 100% | 2023-10-31 |
| CVE-2024-7593 KEV | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to… | Patch first | 9.8 critical | 100% | 2024-08-13 |
| CVE-2023-35078 KEV | An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application wit… | Patch first | 9.8 critical | 100% | 2023-07-25 |
| CVE-2022-29464 KEV | Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content… | Patch first | 9.8 critical | 100% | 2022-04-18 |
| CVE-2023-4966 KEV | Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) … | Patch first | 9.4 critical | 100% | 2023-10-10 |
| CVE-2021-34473 KEV | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch first | 9.1 critical | 100% | 2021-07-14 |
| CVE-2024-21887 KEV | A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated… | Patch first | 9.1 critical | 100% | 2024-01-12 |
| CVE-2021-40438 KEV | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP S… | Patch first | 9.0 critical | 100% | 2021-09-16 |
| CVE-2023-32315 KEV | Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be… | Patch first | 8.6 high | 100% | 2023-05-26 |
| CVE-2024-21893 KEV | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti… | Patch first | 8.2 high | 100% | 2024-01-31 |
| CVE-2017-7921 KEV | An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.… | Patch first | 9.8 critical | 100% | 2017-05-06 |
| CVE-2022-22954 KEV | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious acto… | Patch first | 9.8 critical | 100% | 2022-04-11 |
| CVE-2024-3273 KEV | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to… | Patch first | 7.3 high | 100% | 2024-04-04 |
| CVE-2019-16920 KEV | Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker… | Patch first | 9.8 critical | 100% | 2019-09-27 |
| CVE-2025-49704 KEV | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | Patch first | 8.8 high | 100% | 2025-07-08 |
| CVE-2024-34102 KEV | Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE… | Patch first | 9.8 critical | 100% | 2024-06-13 |
| CVE-2024-13159 KEV | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthent… | Patch first | 9.8 critical | 100% | 2025-01-14 |
| CVE-2023-29300 KEV | Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted… | Patch first | 9.8 critical | 100% | 2023-07-12 |
| CVE-2024-27199 KEV | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible | Patch first | 7.3 high | 100% | 2024-03-04 |
| CVE-2021-34523 KEV | Microsoft Exchange Server Elevation of Privilege Vulnerability | Patch first | 9.0 critical | 100% | 2021-07-14 |
| CVE-2020-9054 KEV | Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, whic… | Patch first | 9.8 critical | 100% | 2020-03-04 |
| CVE-2021-33044 KEV | The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentic… | Patch first | 9.8 critical | 100% | 2021-09-15 |
| CVE-2023-46805 KEV | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restri… | Patch first | 8.2 high | 100% | 2024-01-12 |
| CVE-2023-29357 KEV | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Patch first | 9.8 critical | 100% | 2023-06-14 |
| CVE-2023-22527 KEV | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affe… | Patch first | 9.8 critical | 100% | 2024-01-16 |
| CVE-2021-20090 KEV | A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could… | Patch first | 9.8 critical | 100% | 2021-04-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt