CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,455 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-7238 KEV | Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control. | Patch first | 9.8 critical | 77.1% | 2019-03-21 |
| CVE-2020-13965 KEV | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is amo… | Patch first | 6.1 medium | 76.6% | 2020-06-09 |
| CVE-2022-44698 KEV | Windows SmartScreen Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 76.3% | 2022-12-13 |
| CVE-2026-25089 KEV | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.… | Patch first | 9.8 critical | 76.1% | 2026-06-09 |
| CVE-2023-5631 KEV | Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because o… | Patch first | 6.1 medium | 75.9% | 2023-10-18 |
| CVE-2025-1316 KEV | Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device | Patch first | 9.8 critical | 74.5% | 2025-03-05 |
| CVE-2021-42258 KEV | BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in… | Patch first | 9.8 critical | 74.4% | 2021-10-22 |
| CVE-2018-14667 KEV | The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated… | Patch first | 9.8 critical | 74.2% | 2018-11-06 |
| CVE-2017-8543 KEV | Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Wi… | Patch first | 9.8 critical | 74.2% | 2017-06-15 |
| CVE-2019-1003029 KEV | A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox… | Patch first | 9.9 critical | 73.9% | 2019-03-08 |
| CVE-2025-6205 KEV | A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access… | Patch first | 9.1 critical | 73.3% | 2025-08-04 |
| CVE-2025-2746 KEV | An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 u… | Patch first | 9.8 critical | 73% | 2025-03-24 |
| CVE-2022-20699 KEV | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch first | 10.0 critical | 72.5% | 2022-02-10 |
| CVE-2022-28810 KEV | Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTE… | Patch first | 6.8 medium | 71% | 2022-04-18 |
| CVE-2026-21962 KEV | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Pl… | Patch first | 10.0 critical | 70.9% | 2026-01-20 |
| CVE-2025-20333 KEV | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FT… | Patch first | 9.9 critical | 70.7% | 2025-09-25 |
| CVE-2020-4427 KEV | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with… | Patch first | 9.8 critical | 70% | 2020-05-07 |
| CVE-2021-44026 KEV | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. | Patch first | 9.8 critical | 69.9% | 2021-11-19 |
| CVE-2020-4430 KEV | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker co… | Patch first | 4.3 medium | 68.5% | 2020-05-07 |
| CVE-2021-30657 KEV | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious… | Patch first | 5.5 medium | 68.5% | 2021-09-08 |
| CVE-2025-59718 KEV | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 t… | Patch first | 9.8 critical | 68.3% | 2025-12-09 |
| CVE-2023-28461 KEV | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gate… | Patch first | 9.8 critical | 68.1% | 2023-03-15 |
| CVE-2025-20337 KEV | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the unde… | Patch first | 10.0 critical | 67.8% | 2025-07-16 |
| CVE-2024-57726 KEV | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive perm… | Patch first | 9.9 critical | 66.6% | 2025-01-15 |
| CVE-2025-31125 KEV | Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicit… | Patch first | 5.3 medium | 64.7% | 2025-03-31 |
| CVE-2025-2776 KEV | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functiona… | Patch first | 9.3 critical | 64.4% | 2025-05-07 |
| CVE-2016-20017 KEV | D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016… | Patch first | 9.8 critical | 64.2% | 2022-10-19 |
| CVE-2023-43770 KEV | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/li… | Patch first | 6.1 medium | 63.7% | 2023-09-22 |
| CVE-2015-4068 KEV | Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of ser… | Patch first | 9.1 critical | 63.6% | 2015-05-29 |
| CVE-2021-22681 KEV | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers ar… | Patch first | 9.8 critical | 63.6% | 2021-03-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt