CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
185,351 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-45195 KEV | Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade… | Patch first | 7.5 high | 100% | 2024-09-04 |
| CVE-2025-22457 KEV | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways… | Patch first | 9.0 critical | 100% | 2025-04-03 |
| CVE-2024-1709 KEV | ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allo… | Patch first | 10.0 critical | 100% | 2024-02-21 |
| CVE-2025-59287 KEV | Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | Patch first | 9.8 critical | 100% | 2025-10-14 |
| CVE-2023-4863 KEV | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memor… | Patch first | 8.8 high | 100% | 2023-09-12 |
| CVE-2024-24919 KEV | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote A… | Patch first | 8.6 high | 100% | 2024-05-28 |
| CVE-2021-45046 KEV | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows att… | Patch first | 9.0 critical | 100% | 2021-12-14 |
| CVE-2022-41082 KEV | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch first | 8.0 high | 100% | 2022-10-03 |
| CVE-2020-25506 KEV | D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execu… | Patch first | 9.8 critical | 100% | 2021-02-02 |
| CVE-2024-38475 KEV | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are pe… | Patch first | 9.1 critical | 100% | 2024-07-01 |
| CVE-2022-41040 KEV | Microsoft Exchange Server Elevation of Privilege Vulnerability | Patch first | 8.8 high | 100% | 2022-10-03 |
| CVE-2023-38035 KEV | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authenticat… | Patch first | 9.8 critical | 100% | 2023-08-21 |
| CVE-2024-29824 KEV | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network… | Patch first | 8.8 high | 99.9% | 2024-05-31 |
| CVE-2023-34362 KEV | In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection… | Patch first | 9.8 critical | 99.9% | 2023-06-02 |
| CVE-2021-38647 KEV | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | Patch first | 9.8 critical | 99.9% | 2021-09-15 |
| CVE-2021-39226 KEV | Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with… | Patch first | 9.8 critical | 99.9% | 2021-10-05 |
| CVE-2021-1497 KEV | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform comman… | Patch first | 9.8 critical | 99.9% | 2021-05-06 |
| CVE-2022-35405 KEV | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects… | Patch first | 9.8 critical | 99.9% | 2022-07-19 |
| CVE-2026-10520 KEV | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achiev… | Patch first | 10.0 critical | 99.9% | 2026-06-09 |
| CVE-2021-20038 KEV | A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attac… | Patch first | 9.8 critical | 99.9% | 2021-12-08 |
| CVE-2022-24816 KEV | JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network… | Patch first | 10.0 critical | 99.9% | 2022-04-13 |
| CVE-2024-45519 KEV | The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 someti… | Patch first | 10.0 critical | 99.9% | 2024-10-02 |
| CVE-2019-7481 KEV | Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 ver… | Patch first | 7.5 high | 99.9% | 2019-12-17 |
| CVE-2023-21839 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.… | Patch first | 7.5 high | 99.9% | 2023-01-18 |
| CVE-2023-46604 KEV | The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to… | Patch first | 10.0 critical | 99.9% | 2023-10-27 |
| CVE-2021-44515 KEV | Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in… | Patch first | 9.8 critical | 99.9% | 2021-12-12 |
| CVE-2021-35394 KEV | Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binar… | Patch first | 9.8 critical | 99.9% | 2021-08-16 |
| CVE-2024-0012 KEV | An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface… | Patch first | 9.8 critical | 99.8% | 2024-11-18 |
| CVE-2021-37415 KEV | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. | Patch first | 9.8 critical | 99.8% | 2021-09-01 |
| CVE-2023-38831 KEV | RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs… | Patch first | 7.8 high | 99.8% | 2023-08-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt