CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,529 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
185,355 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-47575 KEV | A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager… | Patch first | 9.8 critical | 94.8% | 2024-10-23 |
| CVE-2020-6287 KEV | SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker… | Patch first | 10.0 critical | 94.7% | 2020-07-14 |
| CVE-2024-9474 KEV | A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface t… | Patch first | 7.2 high | 94.7% | 2024-11-18 |
| CVE-2024-21413 KEV | Microsoft Outlook Remote Code Execution Vulnerability | Patch first | 9.8 critical | 94.7% | 2024-02-13 |
| CVE-2020-14644 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0… | Patch first | 9.8 critical | 94.5% | 2020-07-15 |
| CVE-2025-54236 KEV | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vul… | Patch first | 9.1 critical | 94.5% | 2025-09-09 |
| CVE-2017-18368 KEV | The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remot… | Patch first | 9.8 critical | 94.4% | 2019-05-02 |
| CVE-2024-48248 KEV | NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to rem… | Patch first | 8.6 high | 94.4% | 2025-03-04 |
| CVE-2025-30406 KEV | Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcode… | Patch first | 9.0 critical | 94.3% | 2025-04-03 |
| CVE-2024-55591 KEV | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy vers… | Patch first | 9.8 critical | 94.1% | 2025-01-14 |
| CVE-2025-8088 KEV | A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive fi… | Patch first | 8.8 high | 94.1% | 2025-08-08 |
| CVE-2025-11953 KEV | The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoi… | Patch first | 9.8 critical | 94% | 2025-11-03 |
| CVE-2024-55956 KEV | In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash… | Patch first | 9.8 critical | 94% | 2024-12-13 |
| CVE-2025-24016 KEV | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an… | Patch first | 9.9 critical | 93.8% | 2025-02-10 |
| CVE-2026-21643 KEV | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an un… | Patch first | 9.8 critical | 93.7% | 2026-02-06 |
| CVE-2025-4008 KEV | The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system throu… | Patch first | 8.8 high | 93.7% | 2025-05-21 |
| CVE-2021-26858 KEV | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch first | 7.8 high | 93.7% | 2021-03-03 |
| CVE-2024-28987 KEV | The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access intern… | Patch first | 9.1 critical | 93.3% | 2024-08-21 |
| CVE-2021-44077 KEV | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthentica… | Patch first | 9.8 critical | 93.3% | 2021-11-29 |
| CVE-2018-0802 KEV | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulner… | Patch first | 7.8 high | 93.3% | 2018-01-10 |
| CVE-2020-2551 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected… | Patch first | 9.8 critical | 93.2% | 2020-01-15 |
| CVE-2022-33891 KEV | The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks w… | Patch first | 8.8 high | 93.1% | 2022-07-18 |
| CVE-2021-40870 KEV | An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows… | Patch first | 9.8 critical | 93% | 2021-09-13 |
| CVE-2024-6670 KEV | In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted pa… | Patch first | 9.8 critical | 93% | 2024-08-29 |
| CVE-2025-34291 KEV | Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permiss… | Patch first | 8.8 high | 92.8% | 2025-12-05 |
| CVE-2023-38950 KEV | A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a cra… | Patch first | 7.5 high | 92.5% | 2023-08-03 |
| CVE-2016-3427 KEV | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confid… | Patch first | 9.8 critical | 92.3% | 2016-04-21 |
| CVE-2025-11371 KEV | In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows u… | Patch first | 7.5 high | 92.1% | 2025-10-09 |
| CVE-2022-26258 KEV | D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp. | Patch first | 9.8 critical | 92% | 2022-03-28 |
| CVE-2020-10148 KEV | The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability coul… | Patch first | 9.8 critical | 92% | 2020-12-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt