CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,265 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,616 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-21242 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code exec… | Patch early | 10.0 critical | 74.2% | 2021-01-15 |
| CVE-2022-3218 | Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which… | Patch early | 9.8 critical | 74% | 2022-09-19 |
| CVE-2022-0412 | The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the… | Patch early | 9.8 critical | 74% | 2022-02-28 |
| CVE-2024-31997 | XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as Ve… | Patch early | 9.9 critical | 73.9% | 2024-04-10 |
| CVE-2019-11072 | lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly… | Patch early | 9.8 critical | 73.8% | 2019-04-10 |
| CVE-2021-37918 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | Patch early | 9.8 critical | 73.6% | 2021-10-07 |
| CVE-2021-37926 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | Patch early | 9.8 critical | 73.6% | 2021-10-07 |
| CVE-2022-36100 | XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki… | Patch early | 9.9 critical | 73.6% | 2022-09-08 |
| CVE-2022-34265 | An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if… | Patch early | 9.8 critical | 73.6% | 2022-07-04 |
| CVE-2021-37346 | Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an… | Patch early | 9.8 critical | 73.6% | 2021-08-13 |
| CVE-2022-35711 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could res… | Patch early | 9.8 critical | 73.5% | 2022-10-14 |
| CVE-2024-22320 | IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deser… | Patch early | 9.8 critical | 73.4% | 2024-02-02 |
| CVE-2023-38992 | jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData. | Patch early | 9.8 critical | 73.4% | 2023-07-28 |
| CVE-2023-32165 | D-Link D-View TftpReceiveFileHandler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ar… | Patch early | 9.8 critical | 73.3% | 2024-05-03 |
| CVE-2024-28255 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamle… | Patch early | 9.8 critical | 73.3% | 2024-03-15 |
| CVE-2022-30136 | Windows Network File System Remote Code Execution Vulnerability | Patch early | 9.8 critical | 73.2% | 2022-06-15 |
| CVE-2021-25281 | An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attack… | Patch early | 9.8 critical | 73.1% | 2021-02-27 |
| CVE-2021-28958 | Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password. | Patch early | 9.8 critical | 73.1% | 2021-06-25 |
| CVE-2020-28578 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a specially cr… | Patch early | 9.8 critical | 73% | 2020-11-18 |
| CVE-2018-1000533 | klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can… | Patch early | 9.8 critical | 73% | 2018-06-26 |
| CVE-2025-34299 | Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execut… | Patch early | 9.8 critical | 72.9% | 2025-11-07 |
| CVE-2020-9757 | The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers con… | Patch early | 9.8 critical | 72.8% | 2020-03-04 |
| CVE-2024-43441 | Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 befo… | Patch early | 9.8 critical | 72.8% | 2024-12-24 |
| CVE-2024-27954 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server S… | Patch early | 9.3 critical | 72.8% | 2024-05-17 |
| CVE-2020-8606 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installati… | Patch early | 9.8 critical | 72.7% | 2020-05-27 |
| CVE-2021-22992 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x be… | Patch early | 9.8 critical | 72.7% | 2021-03-31 |
| CVE-2019-12780 | The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple P… | Patch early | 9.8 critical | 72.4% | 2019-06-10 |
| CVE-2021-3197 | An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an… | Patch early | 9.8 critical | 72.3% | 2021-02-27 |
| CVE-2022-35690 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could re… | Patch early | 9.8 critical | 72.2% | 2022-10-14 |
| CVE-2025-2777 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality,… | Patch early | 9.3 critical | 72.2% | 2025-05-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt