CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,208 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,613 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-34992 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute una… | Patch early | 10.0 critical | 80.1% | 2023-10-10 |
| CVE-2022-20705 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch early | 10.0 critical | 80% | 2022-02-10 |
| CVE-2022-38418 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dire… | Patch early | 9.8 critical | 80% | 2022-10-14 |
| CVE-2023-40176 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can exploit a stored XSS… | Patch early | 9.0 critical | 80% | 2023-08-23 |
| CVE-2023-38408 | The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent i… | Patch early | 9.8 critical | 79.7% | 2023-07-20 |
| CVE-2021-41288 | Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API. | Patch early | 9.8 critical | 79.6% | 2021-09-30 |
| CVE-2020-7136 | A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise h… | Patch early | 9.8 critical | 79.5% | 2020-04-30 |
| CVE-2024-2044 | pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is runnin… | Patch early | 9.9 critical | 79.5% | 2024-03-07 |
| CVE-2025-32969 | XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticate… | Patch early | 9.8 critical | 79.4% | 2025-04-23 |
| CVE-2020-13957 | Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote cod… | Patch early | 9.8 critical | 79.3% | 2020-10-13 |
| CVE-2024-8503 | An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stor… | Patch early | 9.8 critical | 79.3% | 2024-09-10 |
| CVE-2021-37350 | Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation. | Patch early | 9.8 critical | 79.3% | 2021-08-13 |
| CVE-2022-23944 | User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | Patch early | 9.1 critical | 79% | 2022-01-25 |
| CVE-2023-50721 | XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration inter… | Patch early | 9.9 critical | 78.8% | 2023-12-15 |
| CVE-2020-28653 | Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (S… | Patch early | 9.8 critical | 78.7% | 2021-02-03 |
| CVE-2019-10692 | In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT s… | Patch early | 9.8 critical | 78.7% | 2019-04-02 |
| CVE-2019-11945 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | Patch early | 9.8 critical | 78.6% | 2019-06-05 |
| CVE-2020-12800 | The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by… | Patch early | 9.8 critical | 78.6% | 2020-06-08 |
| CVE-2025-0107 | An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-dat… | Patch early | 9.8 critical | 78.5% | 2025-01-11 |
| CVE-2023-38545 | This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy t… | Patch early | 9.8 critical | 78.5% | 2023-10-18 |
| CVE-2026-21858 | n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlyi… | Patch early | 10.0 critical | 78.4% | 2026-01-08 |
| CVE-2024-23108 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute un… | Patch early | 10.0 critical | 78.4% | 2024-02-05 |
| CVE-2017-13696 | A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise… | Patch early | 9.8 critical | 78.3% | 2018-01-24 |
| CVE-2024-28075 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse… | Patch early | 9.0 critical | 78% | 2024-05-14 |
| CVE-2024-3408 | man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnera… | Patch early | 9.8 critical | 78% | 2024-06-06 |
| CVE-2016-2108 | The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of servi… | Patch early | 9.8 critical | 77.9% | 2016-05-05 |
| CVE-2020-9294 | An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote una… | Patch early | 9.8 critical | 77.8% | 2020-04-27 |
| CVE-2023-29525 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to cod… | Patch early | 9.9 critical | 77.8% | 2023-04-19 |
| CVE-2022-2560 | This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server. Authenticati… | Patch early | 9.1 critical | 77.7% | 2023-03-29 |
| CVE-2025-6514 | mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response U… | Patch early | 9.6 critical | 77.7% | 2025-07-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt