CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
185,351 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-36401 KEV | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple… | Patch first | 9.8 critical | 99.8% | 2024-07-01 |
| CVE-2025-10035 KEV | A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to… | Patch first | 10.0 critical | 99.8% | 2025-09-18 |
| CVE-2021-34527 KEV | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who su… | Patch first | 8.8 high | 99.8% | 2021-07-02 |
| CVE-2023-29298 KEV | Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vul… | Patch first | 7.5 high | 99.8% | 2023-07-12 |
| CVE-2021-31166 KEV | HTTP Protocol Stack Remote Code Execution Vulnerability | Patch first | 9.8 critical | 99.8% | 2021-05-11 |
| CVE-2022-47966 KEV | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xml… | Patch first | 9.8 critical | 99.8% | 2023-01-18 |
| CVE-2023-3519 KEV | Unauthenticated remote code execution | Patch first | 9.8 critical | 99.7% | 2023-07-19 |
| CVE-2023-38205 KEV | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerabilit… | Patch first | 7.5 high | 99.7% | 2023-09-14 |
| CVE-2020-15505 KEV | A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0,… | Patch first | 9.8 critical | 99.7% | 2020-07-07 |
| CVE-2025-61882 KEV | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that a… | Patch first | 9.8 critical | 99.7% | 2025-10-05 |
| CVE-2021-22054 KEV | VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 cont… | Patch first | 7.5 high | 99.7% | 2021-12-17 |
| CVE-2025-48703 KEV | CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total… | Patch first | 9.0 critical | 99.7% | 2025-09-19 |
| CVE-2022-22965 KEV | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit r… | Patch first | 9.8 critical | 99.6% | 2022-04-01 |
| CVE-2024-5217 KEV | ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. Thi… | Patch first | 9.8 critical | 99.6% | 2024-07-10 |
| CVE-2024-9465 KEV | An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as pas… | Patch first | 9.1 critical | 99.6% | 2024-10-09 |
| CVE-2021-33045 KEV | The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentic… | Patch first | 9.8 critical | 99.6% | 2021-09-15 |
| CVE-2020-16846 KEV | An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell… | Patch first | 9.8 critical | 99.6% | 2020-11-06 |
| CVE-2023-20198 KEV | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating… | Patch first | 10.0 critical | 99.6% | 2023-10-16 |
| CVE-2024-4040 KEV | A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote att… | Patch first | 9.8 critical | 99.5% | 2024-04-22 |
| CVE-2022-42475 KEV | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through… | Patch first | 9.8 critical | 99.5% | 2023-01-02 |
| CVE-2025-31324 KEV | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially mal… | Patch first | 10.0 critical | 99.5% | 2025-04-24 |
| CVE-2023-34048 KEV | vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vC… | Patch first | 9.8 critical | 99.4% | 2023-10-25 |
| CVE-2024-38856 KEV | Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to versio… | Patch first | 9.8 critical | 99.4% | 2024-08-05 |
| CVE-2024-21412 KEV | Internet Shortcut Files Security Feature Bypass Vulnerability | Patch first | 8.1 high | 99.4% | 2024-02-13 |
| CVE-2021-32030 KEV | The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass w… | Patch first | 9.8 critical | 99.4% | 2021-05-06 |
| CVE-2022-0543 KEV | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which co… | Patch first | 10.0 critical | 99.4% | 2022-02-18 |
| CVE-2024-4885 KEV | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.Expo… | Patch first | 9.8 critical | 99.3% | 2024-06-25 |
| CVE-2023-28771 KEV | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FL… | Patch first | 9.8 critical | 99.3% | 2023-04-25 |
| CVE-2020-14750 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.… | Patch first | 9.8 critical | 99.3% | 2020-11-02 |
| CVE-2022-30190 KEV | A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who succe… | Patch first | 7.8 high | 99.2% | 2022-06-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt