CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,218 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,616 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-1181 | A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne… | Patch early | 9.8 critical | 75.8% | 2019-08-14 |
| CVE-2023-29509 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents can… | Patch early | 9.9 critical | 75.7% | 2023-04-16 |
| CVE-2023-29524 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute anything with the ri… | Patch early | 9.9 critical | 75.7% | 2023-04-19 |
| CVE-2014-9390 | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on… | Patch early | 9.8 critical | 75.6% | 2020-02-12 |
| CVE-2024-31465 | XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit righ… | Patch early | 9.9 critical | 75.6% | 2024-04-10 |
| CVE-2020-3247 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authe… | Patch early | 9.8 critical | 75.6% | 2020-04-15 |
| CVE-2023-32243 | Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons f… | Patch early | 9.8 critical | 75.5% | 2023-05-12 |
| CVE-2022-22274 | A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS)… | Patch early | 9.8 critical | 75.5% | 2022-03-25 |
| CVE-2018-17243 | Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection. | Patch early | 9.8 critical | 75.5% | 2018-09-20 |
| CVE-2020-28347 | tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this… | Patch early | 9.8 critical | 75.4% | 2020-11-08 |
| CVE-2021-31856 | A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patte… | Patch early | 9.8 critical | 75.4% | 2021-04-28 |
| CVE-2022-20707 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch early | 10.0 critical | 75.3% | 2022-02-10 |
| CVE-2021-3007 | Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if th… | Patch early | 9.8 critical | 75.3% | 2021-01-04 |
| CVE-2025-1044 | Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected i… | Patch early | 9.8 critical | 75.3% | 2025-02-11 |
| CVE-2023-35885 | CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication. | Patch early | 9.8 critical | 74.9% | 2023-06-20 |
| CVE-2021-41950 | A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the Resourc… | Patch early | 9.1 critical | 74.9% | 2021-11-15 |
| CVE-2022-43671 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection. | Patch early | 9.8 critical | 74.8% | 2022-11-12 |
| CVE-2025-11749 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST A… | Patch early | 9.8 critical | 74.8% | 2025-11-05 |
| CVE-2023-26477 | XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Py… | Patch early | 10.0 critical | 74.8% | 2023-03-02 |
| CVE-2020-14756 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1… | Patch early | 9.8 critical | 74.8% | 2021-01-20 |
| CVE-2020-12124 | A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to ex… | Patch early | 9.8 critical | 74.7% | 2020-10-02 |
| CVE-2022-0169 | The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a S… | Patch early | 9.8 critical | 74.6% | 2022-03-14 |
| CVE-2020-24391 | mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769. | Patch early | 9.8 critical | 74.5% | 2021-03-30 |
| CVE-2021-37538 | Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitr… | Patch early | 9.8 critical | 74.5% | 2021-08-24 |
| CVE-2020-11854 | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerabil… | Patch early | 9.8 critical | 74.4% | 2020-10-27 |
| CVE-2020-3248 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authe… | Patch early | 9.8 critical | 74.4% | 2020-04-15 |
| CVE-2020-10188 | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buf… | Patch early | 9.8 critical | 74.3% | 2020-03-06 |
| CVE-2018-19300 | On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02,… | Patch early | 9.8 critical | 74.3% | 2019-04-11 |
| CVE-2023-23076 | OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules. | Patch early | 9.8 critical | 74.3% | 2023-02-01 |
| CVE-2017-8229 | Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials. If the firmware versi… | Patch early | 9.8 critical | 74.2% | 2019-07-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt