CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,157 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,608 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-28871 | Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure fil… | Patch early | 9.8 critical | 85.8% | 2021-02-10 |
| CVE-2015-7501 | Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Pla… | Patch early | 9.8 critical | 85.6% | 2017-11-09 |
| CVE-2021-31805 | The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double eva… | Patch early | 9.8 critical | 85.4% | 2022-04-12 |
| CVE-2020-35476 | A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a… | Patch early | 9.8 critical | 85.3% | 2020-12-16 |
| CVE-2023-25157 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OG… | Patch early | 9.8 critical | 85.2% | 2023-02-21 |
| CVE-2023-40498 | LG Simple Editor cp Command Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c… | Patch early | 9.8 critical | 85.1% | 2024-05-03 |
| CVE-2023-21716 | Microsoft Word Remote Code Execution Vulnerability | Patch early | 9.8 critical | 84.8% | 2023-02-14 |
| CVE-2022-24697 | Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can… | Patch early | 9.8 critical | 84.8% | 2022-10-13 |
| CVE-2017-17105 | Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote comman… | Patch early | 9.8 critical | 84.6% | 2017-12-19 |
| CVE-2023-25690 | Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affect… | Patch early | 9.8 critical | 84.5% | 2023-03-07 |
| CVE-2022-36974 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication… | Patch early | 9.8 critical | 84.5% | 2023-03-29 |
| CVE-2024-38077 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | Patch early | 9.8 critical | 84.2% | 2024-07-09 |
| CVE-2024-6782 | Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution. | Patch early | 9.8 critical | 84.1% | 2024-08-06 |
| CVE-2023-48022 | Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this r… | Patch early | 9.8 critical | 83.9% | 2023-11-28 |
| CVE-2021-3781 | A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe comma… | Patch early | 9.9 critical | 83.9% | 2022-02-16 |
| CVE-2021-38294 | A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4.… | Patch early | 9.8 critical | 83.8% | 2021-10-25 |
| CVE-2024-32651 | changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Temp… | Patch early | 10.0 critical | 83.6% | 2024-04-26 |
| CVE-2022-29081 | Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass o… | Patch early | 9.8 critical | 83.5% | 2022-04-28 |
| CVE-2022-36981 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication… | Patch early | 9.8 critical | 83.4% | 2023-03-29 |
| CVE-2016-10134 | SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids… | Patch early | 9.8 critical | 83.4% | 2017-02-17 |
| CVE-2021-42392 | The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacke… | Patch early | 9.8 critical | 83.2% | 2022-01-10 |
| CVE-2023-49785 | NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to se… | Patch early | 9.1 critical | 83.2% | 2024-03-12 |
| CVE-2023-40492 | LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete ar… | Patch early | 9.1 critical | 83.1% | 2024-05-03 |
| CVE-2023-40494 | LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrar… | Patch early | 9.1 critical | 83.1% | 2024-05-03 |
| CVE-2023-40502 | LG Simple Editor cropImage Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary f… | Patch early | 9.1 critical | 83.1% | 2024-05-03 |
| CVE-2024-31984 | XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document… | Patch early | 9.9 critical | 83% | 2024-04-10 |
| CVE-2023-26469 | In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server. | Patch early | 9.8 critical | 82.9% | 2023-08-17 |
| CVE-2019-13372 | /web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP… | Patch early | 9.8 critical | 82.5% | 2019-07-06 |
| CVE-2017-9828 | '/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remot… | Patch early | 9.8 critical | 82.5% | 2017-06-23 |
| CVE-2020-27955 | Git LFS 2.12.0 allows Remote Code Execution. | Patch early | 9.8 critical | 82.3% | 2020-11-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt