CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,455 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-47813 KEV | loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. | Patch first | 4.3 medium | 63% | 2025-07-10 |
| CVE-2022-21445 KEV | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions th… | Patch first | 9.8 critical | 62.5% | 2022-04-19 |
| CVE-2024-23113 KEV | A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy v… | Patch first | 9.8 critical | 61.7% | 2024-02-15 |
| CVE-2020-4428 KEV | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Fo… | Patch first | 9.1 critical | 61.7% | 2020-05-07 |
| CVE-2018-4939 KEV | Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vul… | Patch first | 9.8 critical | 61.7% | 2018-05-19 |
| CVE-2015-7755 KEV | Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b… | Patch first | 9.8 critical | 61.1% | 2015-12-19 |
| CVE-2021-22991 KEV | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclos… | Patch first | 9.8 critical | 61.1% | 2021-03-31 |
| CVE-2024-54085 KEV | AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful ex… | Patch first | 9.8 critical | 60.7% | 2025-03-11 |
| CVE-2024-8956 KEV | PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authenti… | Patch first | 9.1 critical | 58.8% | 2024-09-17 |
| CVE-2020-26919 KEV | NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level. | Patch first | 9.8 critical | 57.5% | 2020-10-09 |
| CVE-2025-25181 KEV | A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands v… | Patch first | 5.8 medium | 57.3% | 2025-02-03 |
| CVE-2021-27104 KEV | Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA… | Patch first | 9.8 critical | 56.7% | 2021-02-16 |
| CVE-2019-19006 KEV | Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. | Patch first | 9.8 critical | 55.9% | 2019-11-21 |
| CVE-2022-37055 KEV | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main, | Patch first | 9.8 critical | 55.5% | 2022-08-28 |
| CVE-2018-0125 KEV | A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated… | Patch first | 9.8 critical | 55.2% | 2018-02-08 |
| CVE-2024-38812 KEV | The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCent… | Patch first | 9.8 critical | 54.6% | 2024-09-17 |
| CVE-2020-29557 KEV | An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achie… | Patch first | 9.8 critical | 54.3% | 2021-01-29 |
| CVE-2022-29499 KEV | The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Servi… | Patch first | 9.8 critical | 54.3% | 2022-04-26 |
| CVE-2023-20118 KEV | A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allo… | Patch first | 6.5 medium | 54.1% | 2023-04-13 |
| CVE-2021-22941 KEV | Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the s… | Patch first | 9.8 critical | 53.6% | 2021-09-23 |
| CVE-2021-22175 KEV | When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting… | Patch first | 6.8 medium | 53.4% | 2021-06-11 |
| CVE-2025-14611 KEV | Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degra… | Patch first | 9.8 critical | 53.3% | 2025-12-12 |
| CVE-2023-45249 KEV | Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-6… | Patch first | 9.8 critical | 53.3% | 2024-07-24 |
| CVE-2021-20023 KEV | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote h… | Patch first | 4.9 medium | 51.4% | 2021-04-20 |
| CVE-2025-53690 KEV | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issu… | Patch first | 9.0 critical | 51.1% | 2025-09-03 |
| CVE-2013-7331 KEV | The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC s… | Patch first | 6.5 medium | 50.2% | 2014-02-26 |
| CVE-2020-12812 KEV | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succes… | Patch first | 9.8 critical | 49.3% | 2020-07-24 |
| CVE-2021-22017 KEV | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acces… | Patch first | 5.3 medium | 49.2% | 2021-09-23 |
| CVE-2023-37580 KEV | Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. | Patch first | 6.1 medium | 49.1% | 2023-07-31 |
| CVE-2011-1889 KEV | The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitra… | Patch first | 9.8 critical | 49% | 2011-06-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt