CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,265 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,616 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-2917 | The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path… | Patch early | 9.8 critical | 72.2% | 2023-08-17 |
| CVE-2023-27482 | homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API t… | Patch early | 10.0 critical | 72.2% | 2023-03-08 |
| CVE-2021-33564 | An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a craf… | Patch early | 9.8 critical | 72.1% | 2021-05-29 |
| CVE-2023-30547 | vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 f… | Patch early | 9.8 critical | 72.1% | 2023-04-17 |
| CVE-2024-12084 | A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2len… | Patch early | 9.8 critical | 72.1% | 2025-01-15 |
| CVE-2021-30117 | The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. Detailed desc… | Patch early | 9.8 critical | 72.1% | 2021-07-09 |
| CVE-2020-4429 | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker c… | Patch early | 9.8 critical | 72% | 2020-05-07 |
| CVE-2024-49112 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Patch early | 9.8 critical | 71.9% | 2024-12-12 |
| CVE-2023-2825 | An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability t… | Patch early | 10.0 critical | 71.6% | 2023-05-26 |
| CVE-2022-1386 | The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate… | Patch early | 9.8 critical | 71.4% | 2022-05-16 |
| CVE-2019-0547 | A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows… | Patch early | 9.8 critical | 71.4% | 2019-01-08 |
| CVE-2021-28480 | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch early | 9.8 critical | 71.2% | 2021-04-13 |
| CVE-2018-2893 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… | Patch early | 9.8 critical | 71.2% | 2018-07-18 |
| CVE-2023-45138 | Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Starting in version 0.11 and prio… | Patch early | 10.0 critical | 71.2% | 2023-10-12 |
| CVE-2020-4211 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP c… | Patch early | 9.8 critical | 71.1% | 2020-02-24 |
| CVE-2020-2950 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported… | Patch early | 9.8 critical | 71% | 2020-04-15 |
| CVE-2019-5620 | ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function. | Patch early | 9.8 critical | 70.9% | 2020-04-29 |
| CVE-2024-22729 | NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page. | Patch early | 9.8 critical | 70.8% | 2024-01-25 |
| CVE-2021-45467 | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to regis… | Patch early | 9.8 critical | 70.7% | 2022-12-26 |
| CVE-2018-17532 | Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi an… | Patch early | 9.8 critical | 70.7% | 2018-10-15 |
| CVE-2022-47523 | Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection. | Patch early | 9.8 critical | 70.6% | 2023-01-05 |
| CVE-2024-38063 | Windows TCP/IP Remote Code Execution Vulnerability | Patch early | 9.8 critical | 70.6% | 2024-08-13 |
| CVE-2023-20864 | VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Opera… | Patch early | 9.8 critical | 70.4% | 2023-04-20 |
| CVE-2022-28381 | Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TC… | Patch early | 9.8 critical | 70.4% | 2022-04-03 |
| CVE-2022-26133 | SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 a… | Patch early | 9.8 critical | 70.4% | 2022-04-20 |
| CVE-2023-32071 | XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to… | Patch early | 9.0 critical | 70.4% | 2023-05-09 |
| CVE-2021-35393 | Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usua… | Patch early | 9.8 critical | 70.3% | 2021-08-16 |
| CVE-2021-42847 | Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files. | Patch early | 9.8 critical | 70.3% | 2021-11-11 |
| CVE-2023-29711 | An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted GET reque… | Patch early | 9.8 critical | 70.3% | 2023-06-22 |
| CVE-2016-6309 | statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of ser… | Patch early | 9.8 critical | 70.2% | 2016-09-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt