CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,165 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,608 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-26120 | Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring. | Patch early | 9.8 critical | 82.3% | 2021-02-22 |
| CVE-2025-49844 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua… | Patch early | 9.9 critical | 82.3% | 2025-10-03 |
| CVE-2018-17246 | Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console… | Patch early | 9.8 critical | 82.3% | 2018-12-20 |
| CVE-2020-9465 | An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauth… | Patch early | 9.8 critical | 82.2% | 2020-02-28 |
| CVE-2023-1698 | In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which… | Patch early | 9.8 critical | 82% | 2023-05-15 |
| CVE-2023-38096 | NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa… | Patch early | 9.8 critical | 82% | 2024-05-03 |
| CVE-2023-36469 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile… | Patch early | 9.9 critical | 82% | 2023-06-29 |
| CVE-2020-7200 | A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow… | Patch early | 9.8 critical | 81.9% | 2020-12-18 |
| CVE-2023-46263 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve… | Patch early | 9.8 critical | 81.9% | 2023-12-19 |
| CVE-2021-25114 | The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users)… | Patch early | 9.8 critical | 81.8% | 2022-02-07 |
| CVE-2023-43177 | CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes. | Patch early | 9.8 critical | 81.8% | 2023-11-18 |
| CVE-2016-10372 | The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as… | Patch early | 9.8 critical | 81.8% | 2017-05-16 |
| CVE-2015-7871 | Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. | Patch early | 9.8 critical | 81.8% | 2017-08-07 |
| CVE-2020-27868 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not re… | Patch early | 9.8 critical | 81.8% | 2021-02-12 |
| CVE-2024-5806 | Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer:… | Patch early | 9.1 critical | 81.5% | 2024-06-25 |
| CVE-2021-2456 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). The suppo… | Patch early | 9.8 critical | 81.4% | 2021-07-21 |
| CVE-2021-33543 | Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user aut… | Patch early | 9.8 critical | 81.3% | 2021-09-13 |
| CVE-2021-30128 | Apache OFBiz has unsafe deserialization prior to 17.12.07 version | Patch early | 9.8 critical | 81.2% | 2021-04-27 |
| CVE-2019-17602 | An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depend… | Patch early | 9.8 critical | 81.1% | 2019-10-15 |
| CVE-2022-31704 | The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive fi… | Patch early | 9.8 critical | 81% | 2023-01-26 |
| CVE-2021-38540 | The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint t… | Patch early | 9.8 critical | 80.9% | 2021-09-09 |
| CVE-2025-21298 | Windows OLE Remote Code Execution Vulnerability | Patch early | 9.8 critical | 80.9% | 2025-01-14 |
| CVE-2023-50164 | An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which… | Patch early | 9.8 critical | 80.8% | 2023-12-07 |
| CVE-2024-2876 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to… | Patch early | 9.8 critical | 80.6% | 2024-05-02 |
| CVE-2022-34715 | Windows Network File System Remote Code Execution Vulnerability | Patch early | 9.8 critical | 80.4% | 2022-08-09 |
| CVE-2022-37860 | The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerabili… | Patch early | 9.8 critical | 80.4% | 2022-09-12 |
| CVE-2024-4990 | In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value pa… | Patch early | 9.1 critical | 80.2% | 2025-03-20 |
| CVE-2024-56325 | Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Exampl… | Patch early | 9.8 critical | 80.2% | 2025-04-01 |
| CVE-2023-44353 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could… | Patch early | 9.8 critical | 80.2% | 2023-11-17 |
| CVE-2023-39143 | PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads t… | Patch early | 9.8 critical | 80.1% | 2023-08-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt