CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,157 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,608 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-32563 | An unauthenticated attacker could achieve the code execution through a RemoteControl server. | Patch early | 9.8 critical | 89.1% | 2023-08-10 |
| CVE-2020-12720 | vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control. | Patch early | 9.8 critical | 88.9% | 2020-05-08 |
| CVE-2021-45456 | Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch betw… | Patch early | 9.8 critical | 88.9% | 2022-01-06 |
| CVE-2023-39361 | Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_vi… | Patch early | 9.8 critical | 88.8% | 2023-09-05 |
| CVE-2023-40504 | LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… | Patch early | 9.8 critical | 88.7% | 2024-05-03 |
| CVE-2023-46731 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section URL… | Patch early | 10.0 critical | 88.5% | 2023-11-06 |
| CVE-2020-3243 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authe… | Patch early | 9.8 critical | 88.4% | 2020-04-15 |
| CVE-2018-19207 | The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $w… | Patch early | 9.8 critical | 88.1% | 2018-11-12 |
| CVE-2022-0540 | A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This af… | Patch early | 9.8 critical | 88.1% | 2022-04-20 |
| CVE-2020-8772 | The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows… | Patch early | 9.8 critical | 88% | 2020-02-06 |
| CVE-2024-36104 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before… | Patch early | 9.1 critical | 87.9% | 2024-06-04 |
| CVE-2021-3711 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this… | Patch early | 9.8 critical | 87.8% | 2021-08-24 |
| CVE-2023-46359 | An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to exe… | Patch early | 9.8 critical | 87.6% | 2024-02-06 |
| CVE-2003-0545 | Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL… | Patch early | 9.8 critical | 87.5% | 2003-11-17 |
| CVE-2020-10546 | rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in… | Patch early | 9.8 critical | 87.3% | 2020-06-04 |
| CVE-2021-3122 | CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to po… | Patch early | 9.8 critical | 87.3% | 2021-02-07 |
| CVE-2018-15381 | A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands… | Patch early | 9.8 critical | 87.3% | 2018-11-08 |
| CVE-2020-26948 | Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter. | Patch early | 9.8 critical | 87.2% | 2020-10-10 |
| CVE-2022-31706 | The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system… | Patch early | 9.8 critical | 87.1% | 2023-01-26 |
| CVE-2021-40323 | Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection. | Patch early | 9.8 critical | 86.8% | 2021-10-04 |
| CVE-2023-35813 | Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. | Patch early | 9.8 critical | 86.7% | 2023-06-17 |
| CVE-2020-10915 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not re… | Patch early | 9.8 critical | 86.6% | 2020-04-22 |
| CVE-2018-17153 | It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated a… | Patch early | 9.8 critical | 86.6% | 2018-09-18 |
| CVE-2023-28121 | An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an e… | Patch early | 9.8 critical | 86.5% | 2023-04-12 |
| CVE-2021-45232 | In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all… | Patch early | 9.8 critical | 86.3% | 2021-12-27 |
| CVE-2022-2992 | A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achi… | Patch early | 9.9 critical | 86.2% | 2022-10-17 |
| CVE-2016-20016 | MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenti… | Patch early | 9.8 critical | 86.2% | 2022-10-19 |
| CVE-2024-29973 | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.1… | Patch early | 9.8 critical | 86.1% | 2024-06-04 |
| CVE-2024-3094 | Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma bui… | Patch early | 10.0 critical | 86% | 2024-03-29 |
| CVE-2020-17523 | Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. | Patch early | 9.8 critical | 85.9% | 2021-02-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt