CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,208 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,613 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-35150 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to vers… | Patch early | 9.9 critical | 77.7% | 2023-06-23 |
| CVE-2024-1698 | The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQ… | Patch early | 9.8 critical | 77.6% | 2024-02-27 |
| CVE-2024-1512 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user'… | Patch early | 9.8 critical | 77.6% | 2024-02-17 |
| CVE-2019-0192 | In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it… | Patch early | 9.8 critical | 77.5% | 2019-03-07 |
| CVE-2018-0127 | A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unaut… | Patch early | 9.8 critical | 77.5% | 2018-02-08 |
| CVE-2020-11532 | Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attack… | Patch early | 9.8 critical | 77.5% | 2020-05-08 |
| CVE-2018-1270 | Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over… | Patch early | 9.8 critical | 77.5% | 2018-04-06 |
| CVE-2022-25149 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~… | Patch early | 9.8 critical | 77.5% | 2022-02-24 |
| CVE-2020-9850 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iT… | Patch early | 9.8 critical | 77.4% | 2020-06-09 |
| CVE-2024-8877 | Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database o… | Patch early | 9.8 critical | 77.3% | 2024-09-25 |
| CVE-2022-29013 | A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a cra… | Patch early | 9.8 critical | 76.9% | 2022-06-09 |
| CVE-2024-5932 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… | Patch early | 10.0 critical | 76.8% | 2024-08-20 |
| CVE-2016-3236 | The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows… | Patch early | 9.8 critical | 76.8% | 2016-06-16 |
| CVE-2021-41303 | Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should… | Patch early | 9.8 critical | 76.7% | 2021-09-17 |
| CVE-2022-2185 | A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.… | Patch early | 9.9 critical | 76.7% | 2022-07-01 |
| CVE-2024-22120 | Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip"… | Patch early | 9.1 critical | 76.6% | 2024-05-17 |
| CVE-2022-45699 | Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary comman… | Patch early | 9.8 critical | 76.6% | 2023-02-10 |
| CVE-2020-13638 | lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fi… | Patch early | 9.8 critical | 76.6% | 2020-11-13 |
| CVE-2021-2394 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0… | Patch early | 9.8 critical | 76.6% | 2021-07-21 |
| CVE-2024-32640 | MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL inject… | Patch early | 9.8 critical | 76.6% | 2025-08-11 |
| CVE-2022-36099 | XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 a… | Patch early | 9.9 critical | 76.3% | 2022-09-08 |
| CVE-2020-35951 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.p… | Patch early | 9.9 critical | 76.3% | 2021-01-01 |
| CVE-2022-34721 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | Patch early | 9.8 critical | 76.2% | 2022-09-13 |
| CVE-2025-6389 | The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pag… | Patch early | 9.8 critical | 76.1% | 2025-11-25 |
| CVE-2024-36404 | GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) i… | Patch early | 9.8 critical | 76.1% | 2024-07-02 |
| CVE-2021-41653 | The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a cra… | Patch early | 9.8 critical | 76% | 2021-11-13 |
| CVE-2022-26937 | Windows Network File System Remote Code Execution Vulnerability | Patch early | 9.8 critical | 76% | 2022-05-10 |
| CVE-2024-41730 | In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a log… | Patch early | 9.8 critical | 75.9% | 2024-08-13 |
| CVE-2025-48827 | vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.… | Patch early | 10.0 critical | 75.8% | 2025-05-27 |
| CVE-2023-48085 | Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php. | Patch early | 9.8 critical | 75.8% | 2023-12-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt