CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,152 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,608 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-9047 | The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.p… | Patch early | 9.8 critical | 93.3% | 2024-10-12 |
| CVE-2020-35846 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. | Patch early | 9.8 critical | 93.3% | 2020-12-30 |
| CVE-2016-7552 | On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated att… | Patch early | 9.8 critical | 93.2% | 2017-04-12 |
| CVE-2024-45507 | Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach… | Patch early | 9.8 critical | 93.2% | 2024-09-04 |
| CVE-2021-27905 | The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter t… | Patch early | 9.8 critical | 93.1% | 2021-04-13 |
| CVE-2024-2389 | In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified. An unauthenticated user can… | Patch early | 10.0 critical | 93% | 2024-04-02 |
| CVE-2021-37539 | Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution. | Patch early | 9.8 critical | 92.9% | 2021-09-27 |
| CVE-2024-45216 | Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authent… | Patch early | 9.8 critical | 92.7% | 2024-10-16 |
| CVE-2016-7547 | A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interfa… | Patch early | 9.8 critical | 92.7% | 2017-04-12 |
| CVE-2022-40022 | Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. | Patch early | 9.8 critical | 92.5% | 2023-02-13 |
| CVE-2021-25282 | An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal. | Patch early | 9.1 critical | 92.4% | 2021-02-27 |
| CVE-2022-29535 | Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. | Patch early | 9.8 critical | 91.8% | 2022-05-05 |
| CVE-2023-37462 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.… | Patch early | 9.9 critical | 91.6% | 2023-07-14 |
| CVE-2016-3510 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers… | Patch early | 9.8 critical | 91.4% | 2016-07-21 |
| CVE-2024-11320 | Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pa… | Patch early | 9.8 critical | 91% | 2024-11-21 |
| CVE-2021-22962 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. | Patch early | 9.1 critical | 91% | 2023-12-19 |
| CVE-2022-26809 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Patch early | 9.8 critical | 91% | 2022-04-15 |
| CVE-2022-36553 | Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi. | Patch early | 9.8 critical | 90.9% | 2022-08-29 |
| CVE-2022-31137 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code executio… | Patch early | 10.0 critical | 90.6% | 2022-07-08 |
| CVE-2023-37582 | The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5… | Patch early | 9.8 critical | 90.4% | 2023-07-12 |
| CVE-2023-6875 | The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized a… | Patch early | 9.8 critical | 90.3% | 2024-01-11 |
| CVE-2023-46264 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve… | Patch early | 9.8 critical | 90.2% | 2023-12-19 |
| CVE-2024-5276 | A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data. Likely impacts include creation of admin… | Patch early | 9.8 critical | 90.1% | 2024-06-25 |
| CVE-2024-7954 | The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and un… | Patch early | 9.8 critical | 90.1% | 2024-08-23 |
| CVE-2020-11984 | Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE | Patch early | 9.8 critical | 90% | 2020-08-07 |
| CVE-2020-17132 | Microsoft Exchange Remote Code Execution Vulnerability | Patch early | 9.1 critical | 89.9% | 2020-12-10 |
| CVE-2017-5645 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a s… | Patch early | 9.8 critical | 89.8% | 2017-04-17 |
| CVE-2024-1071 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable… | Patch early | 9.8 critical | 89.4% | 2024-03-13 |
| CVE-2024-29972 | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.2… | Patch early | 9.8 critical | 89.3% | 2024-06-04 |
| CVE-2020-35489 | The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename… | Patch early | 10.0 critical | 89.3% | 2020-12-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt