CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,579 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
185,367 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-7238 KEV | Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control. | Patch first | 9.8 critical | 77.1% | 2019-03-21 |
| CVE-2021-38406 KEV | Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could r… | Patch first | 7.8 high | 76.4% | 2021-09-17 |
| CVE-2023-44221 KEV | Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative priv… | Patch first | 7.2 high | 76.3% | 2023-12-05 |
| CVE-2026-25089 KEV | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.… | Patch first | 9.8 critical | 76.1% | 2026-06-09 |
| CVE-2021-30860 KEV | An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8,… | Patch first | 7.8 high | 76% | 2021-08-24 |
| CVE-2021-25298 KEV | Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/c… | Patch first | 8.8 high | 75.1% | 2021-02-15 |
| CVE-2025-1316 KEV | Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device | Patch first | 9.8 critical | 74.5% | 2025-03-05 |
| CVE-2021-42258 KEV | BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in… | Patch first | 9.8 critical | 74.4% | 2021-10-22 |
| CVE-2018-14667 KEV | The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated… | Patch first | 9.8 critical | 74.2% | 2018-11-06 |
| CVE-2017-8543 KEV | Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Wi… | Patch first | 9.8 critical | 74.2% | 2017-06-15 |
| CVE-2024-21182 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.… | Patch first | 7.5 high | 74.2% | 2024-07-16 |
| CVE-2021-40449 KEV | Win32k Elevation of Privilege Vulnerability | Patch first | 7.8 high | 74.1% | 2021-10-13 |
| CVE-2019-1003029 KEV | A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox… | Patch first | 9.9 critical | 73.9% | 2019-03-08 |
| CVE-2025-40536 KEV | SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated atta… | Patch first | 8.1 high | 73.6% | 2026-01-28 |
| CVE-2025-6205 KEV | A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access… | Patch first | 9.1 critical | 73.3% | 2025-08-04 |
| CVE-2021-42278 KEV | Active Directory Domain Services Elevation of Privilege Vulnerability | Patch first | 7.5 high | 73.3% | 2021-11-10 |
| CVE-2023-47565 KEV | An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerabilit… | Patch first | 8.0 high | 73.3% | 2023-12-08 |
| CVE-2025-2746 KEV | An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 u… | Patch first | 9.8 critical | 73% | 2025-03-24 |
| CVE-2020-5741 KEV | Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code. | Patch first | 7.2 high | 72.9% | 2020-05-08 |
| CVE-2018-8414 KEV | A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vu… | Patch first | 8.8 high | 72.9% | 2018-08-15 |
| CVE-2022-20699 KEV | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch first | 10.0 critical | 72.5% | 2022-02-10 |
| CVE-2021-25296 KEV | Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/w… | Patch first | 8.8 high | 72.2% | 2021-02-15 |
| CVE-2025-30066 KEV | tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on… | Patch first | 8.6 high | 72.1% | 2025-03-15 |
| CVE-2012-1856 KEV | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and… | Patch first | 8.8 high | 72% | 2012-08-15 |
| CVE-2020-3259 KEV | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co… | Patch first | 7.5 high | 71.8% | 2020-05-06 |
| CVE-2026-21962 KEV | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Pl… | Patch first | 10.0 critical | 70.9% | 2026-01-20 |
| CVE-2026-21509 KEV | Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. | Patch first | 7.8 high | 70.8% | 2026-01-26 |
| CVE-2024-20353 KEV | A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) So… | Patch first | 8.6 high | 70.7% | 2024-04-24 |
| CVE-2025-20333 KEV | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FT… | Patch first | 9.9 critical | 70.7% | 2025-09-25 |
| CVE-2020-36193 KEV | Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue t… | Patch first | 7.5 high | 70.6% | 2021-01-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt