CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,143 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-09-30
36,608 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-40300 | Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 h… | Patch early | 9.8 critical | 99.1% | 2022-09-16 |
| CVE-2022-39986 | A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter i… | Patch early | 9.8 critical | 99.1% | 2023-08-01 |
| CVE-2021-21978 | VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorizat… | Patch early | 9.8 critical | 99% | 2021-03-03 |
| CVE-2023-38646 | Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the serve… | Patch early | 9.8 critical | 98.7% | 2023-07-21 |
| CVE-2024-29895 | Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthen… | Patch early | 10.0 critical | 98.5% | 2024-05-14 |
| CVE-2022-43781 | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control the… | Patch early | 9.8 critical | 98.1% | 2022-11-17 |
| CVE-2022-2024 | OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11. | Patch early | 9.8 critical | 97.8% | 2023-02-25 |
| CVE-2021-26295 | Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFB… | Patch early | 9.8 critical | 97.8% | 2021-03-22 |
| CVE-2016-10108 | Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg p… | Patch early | 9.8 critical | 97.8% | 2017-01-03 |
| CVE-2022-28219 | Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. | Patch early | 9.8 critical | 97.2% | 2022-04-05 |
| CVE-2021-37344 | Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS… | Patch early | 9.8 critical | 96.8% | 2021-08-13 |
| CVE-2023-35708 | In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection… | Patch early | 9.8 critical | 96.7% | 2023-06-16 |
| CVE-2020-28188 | Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/ma… | Patch early | 9.8 critical | 96.6% | 2020-12-24 |
| CVE-2023-51467 | The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code | Patch early | 9.8 critical | 96% | 2023-12-26 |
| CVE-2023-21554 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Patch early | 9.8 critical | 95.5% | 2023-04-11 |
| CVE-2023-49070 | Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Use… | Patch early | 9.8 critical | 95.4% | 2023-12-05 |
| CVE-2023-36934 | In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0… | Patch early | 9.1 critical | 95.2% | 2023-07-05 |
| CVE-2022-0342 | An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware ver… | Patch early | 9.8 critical | 95.1% | 2022-03-28 |
| CVE-2019-10173 | It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has… | Patch early | 9.8 critical | 95% | 2019-07-23 |
| CVE-2020-13167 | Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a c… | Patch early | 9.8 critical | 95% | 2020-05-19 |
| CVE-2024-9264 | The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficien… | Patch early | 9.9 critical | 94.9% | 2024-10-18 |
| CVE-2020-6754 | dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $T… | Patch early | 9.8 critical | 94.8% | 2020-02-05 |
| CVE-2023-24941 | Windows Network File System Remote Code Execution Vulnerability | Patch early | 9.8 critical | 94.7% | 2023-05-09 |
| CVE-2024-8517 | SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operat… | Patch early | 9.8 critical | 94.6% | 2024-09-06 |
| CVE-2020-14092 | The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection. | Patch early | 9.8 critical | 94.5% | 2020-07-02 |
| CVE-2023-41892 | Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations befor… | Patch early | 10.0 critical | 94.2% | 2023-09-13 |
| CVE-2024-27956 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This i… | Patch early | 9.9 critical | 94.1% | 2024-03-21 |
| CVE-2021-31474 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Aut… | Patch early | 9.8 critical | 93.9% | 2021-05-21 |
| CVE-2024-21650 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code executio… | Patch early | 10.0 critical | 93.5% | 2024-01-08 |
| CVE-2021-27850 | A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,… | Patch early | 9.8 critical | 93.5% | 2021-04-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt