CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,528 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,458 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-23227 KEV | NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because o… | Patch first | 9.8 critical | 48.5% | 2022-01-14 |
| CVE-2021-26829 KEV | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. | Patch first | 5.4 medium | 48.1% | 2021-06-11 |
| CVE-2023-48365 KEV | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of… | Patch first | 9.6 critical | 47.5% | 2023-11-15 |
| CVE-2026-39808 KEV | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.… | Patch first | 9.8 critical | 47.4% | 2026-04-14 |
| CVE-2021-22893 KEV | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Puls… | Patch first | 10.0 critical | 47.2% | 2021-04-23 |
| CVE-2022-39197 KEV | An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the C… | Patch first | 6.1 medium | 46.4% | 2022-09-22 |
| CVE-2024-43573 KEV | Windows MSHTML Platform Spoofing Vulnerability | Patch first | 6.5 medium | 46.1% | 2024-10-08 |
| CVE-2026-12569 KEV | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited th… | Patch first | 9.8 critical | 46% | 2026-06-18 |
| CVE-2026-34910 KEV | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command I… | Patch first | 10.0 critical | 45.8% | 2026-05-22 |
| CVE-2017-6862 KEV | NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and re… | Patch first | 9.8 critical | 45.7% | 2017-05-26 |
| CVE-2013-3900 KEV | Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and… | Patch first | 5.5 medium | 44.6% | 2013-12-11 |
| CVE-2020-15999 KEV | Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafte… | Patch first | 9.6 critical | 44.3% | 2020-11-03 |
| CVE-2024-9379 KEV | SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrar… | Patch first | 6.5 medium | 43.8% | 2024-10-08 |
| CVE-2025-2775 KEV | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionalit… | Patch first | 9.3 critical | 43% | 2025-05-07 |
| CVE-2023-49105 KEV | An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the use… | Patch first | 9.8 critical | 42.9% | 2023-11-21 |
| CVE-2026-20131 KEV | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote… | Patch first | 10.0 critical | 42.7% | 2026-03-04 |
| CVE-2020-12271 KEV | A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April… | Patch first | 9.8 critical | 42.4% | 2020-04-27 |
| CVE-2026-48282 KEV | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vuln… | Patch first | 10.0 critical | 42.4% | 2026-06-30 |
| CVE-2019-16928 KEV | Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_… | Patch first | 9.8 critical | 41.6% | 2019-09-27 |
| CVE-2021-34448 KEV | Scripting Engine Memory Corruption Vulnerability | Patch first | 6.8 medium | 40.1% | 2021-07-16 |
| CVE-2021-20016 KEV | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username… | Patch first | 9.8 critical | 40% | 2021-02-04 |
| CVE-2021-27860 KEV | A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a rem… | Patch first | 9.8 critical | 39.8% | 2021-12-08 |
| CVE-2010-5330 KEV | On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized… | Patch first | 9.8 critical | 39.4% | 2019-06-11 |
| CVE-2021-38163 KEV | SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user… | Patch first | 9.9 critical | 36% | 2021-09-14 |
| CVE-2022-31199 KEV | Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server a… | Patch first | 9.8 critical | 36% | 2022-11-08 |
| CVE-2021-39935 KEV | An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, a… | Patch first | 6.8 medium | 35.6% | 2021-12-13 |
| CVE-2026-20316 KEV | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log… | Patch first | 5.3 medium | 35.1% | 2026-07-29 |
| CVE-2020-2509 KEV | A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrar… | Patch first | 9.8 critical | 34% | 2021-04-17 |
| CVE-2018-13383 KEV | A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1… | Patch first | 4.3 medium | 33.6% | 2019-05-29 |
| CVE-2015-0071 KEV | Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explore… | Patch first | 6.5 medium | 33.6% | 2015-02-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt