CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,436 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-26
185,314 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-7169 KEV EXP | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which… | Patch first | 9.8 critical | 99.9% | 2014-09-25 |
| CVE-2024-27198 KEV EXP | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible | Patch first | 9.8 critical | 99.9% | 2024-03-04 |
| CVE-2022-22963 KEV EXP | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a… | Patch first | 9.8 critical | 99.9% | 2022-04-01 |
| CVE-2025-24813 KEV EXP | Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded… | Patch first | 9.8 critical | 99.9% | 2025-03-10 |
| CVE-2024-32113 KEV EXP | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 1… | Patch first | 9.8 critical | 99.9% | 2024-05-08 |
| CVE-2019-0604 KEV EXP | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka… | Patch first | 9.8 critical | 99.9% | 2019-03-05 |
| CVE-2019-3396 KEV EXP | The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the f… | Patch first | 9.8 critical | 99.9% | 2019-03-25 |
| CVE-2018-0296 KEV EXP | A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affect… | Patch first | 7.5 high | 99.9% | 2018-06-07 |
| CVE-2015-1427 KEV EXP | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism an… | Patch first | 9.8 critical | 99.9% | 2015-02-17 |
| CVE-2020-7961 KEV EXP | Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSO… | Patch first | 9.8 critical | 99.9% | 2020-03-20 |
| CVE-2021-22986 KEV EXP | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ… | Patch first | 9.8 critical | 99.9% | 2021-03-31 |
| CVE-2014-0497 KEV EXP | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.33… | Patch first | 9.8 critical | 99.9% | 2014-02-05 |
| CVE-2022-35914 KEV EXP | /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection. | Patch first | 9.8 critical | 99.9% | 2022-09-19 |
| CVE-2021-27065 KEV EXP | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch first | 7.8 high | 99.9% | 2021-03-03 |
| CVE-2019-1653 KEV EXP | A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthentica… | Patch first | 7.5 high | 99.9% | 2019-01-24 |
| CVE-2021-36260 KEV EXP | A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vuln… | Patch first | 9.8 critical | 99.9% | 2021-09-22 |
| CVE-2021-21972 KEV EXP | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 44… | Patch first | 9.8 critical | 99.9% | 2021-02-24 |
| CVE-2025-24893 KEV EXP | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code e… | Patch first | 9.8 critical | 99.9% | 2025-02-20 |
| CVE-2022-46169 KEV EXP | Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected v… | Patch first | 9.8 critical | 99.8% | 2022-12-05 |
| CVE-2017-7269 KEV EXP | Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003… | Patch first | 9.8 critical | 99.8% | 2017-03-27 |
| CVE-2020-0796 KEV EXP | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka '… | Patch first | 10.0 critical | 99.8% | 2020-03-12 |
| CVE-2016-6277 KEV EXP | NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.B… | Patch first | 8.8 high | 99.8% | 2016-12-14 |
| CVE-2025-55182 KEV EXP | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the f… | Patch first | 10.0 critical | 99.8% | 2025-12-03 |
| CVE-2022-1040 KEV EXP | An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 a… | Patch first | 9.8 critical | 99.8% | 2022-03-25 |
| CVE-2025-32432 KEV EXP | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15… | Patch first | 10.0 critical | 99.8% | 2025-04-25 |
| CVE-2019-11043 KEV EXP | In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM modul… | Patch first | 8.7 high | 99.8% | 2019-10-28 |
| CVE-2020-13927 KEV EXP | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to use… | Patch first | 9.8 critical | 99.8% | 2020-11-10 |
| CVE-2025-25257 KEV EXP | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.… | Patch first | 9.8 critical | 99.8% | 2025-07-17 |
| CVE-2019-18935 KEV EXP | Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploit… | Patch first | 9.8 critical | 99.7% | 2019-12-11 |
| CVE-2021-22205 KEV EXP | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passe… | Patch first | 10.0 critical | 99.7% | 2021-04-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt