CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,331 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,621 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-4350 | Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager… | Patch early | 9.8 critical | 70.2% | 2016-05-09 |
| CVE-2024-53677 | File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances thi… | Patch early | 9.8 critical | 70.1% | 2024-12-11 |
| CVE-2021-32682 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerab… | Patch early | 9.8 critical | 69.9% | 2021-06-14 |
| CVE-2022-44456 | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the p… | Patch early | 9.8 critical | 69.9% | 2022-12-19 |
| CVE-2021-21805 | An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTT… | Patch early | 9.8 critical | 69.8% | 2021-08-05 |
| CVE-2017-18044 | A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside th… | Patch early | 9.8 critical | 69.8% | 2018-01-19 |
| CVE-2023-1177 | Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1. | Patch early | 9.3 critical | 69.7% | 2023-03-24 |
| CVE-2023-3368 | Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code… | Patch early | 9.8 critical | 69.7% | 2023-11-28 |
| CVE-2023-22463 | KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys fo… | Patch early | 9.8 critical | 69.7% | 2023-01-04 |
| CVE-2023-26801 | LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injec… | Patch early | 9.8 critical | 69.7% | 2023-03-26 |
| CVE-2023-5074 | Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28 | Patch early | 9.8 critical | 69.6% | 2023-09-20 |
| CVE-2019-17444 | Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow un… | Patch early | 9.8 critical | 69.4% | 2020-10-12 |
| CVE-2020-7388 | Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attac… | Patch early | 10.0 critical | 69.4% | 2021-07-22 |
| CVE-2023-40497 | LG Simple Editor saveXml Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code… | Patch early | 9.8 critical | 69.4% | 2024-05-03 |
| CVE-2021-33690 | Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions -… | Patch early | 9.9 critical | 69.1% | 2021-09-15 |
| CVE-2019-12196 | A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute a… | Patch early | 9.8 critical | 69.1% | 2019-06-05 |
| CVE-2019-17571 | Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbit… | Patch early | 9.8 critical | 69.1% | 2019-12-20 |
| CVE-2017-5791 | The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via uns… | Patch early | 9.8 critical | 68.9% | 2017-10-11 |
| CVE-2014-9614 | The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to ob… | Patch early | 9.8 critical | 68.7% | 2020-02-19 |
| CVE-2019-0626 | A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Wi… | Patch early | 9.8 critical | 68.6% | 2019-03-05 |
| CVE-2020-13117 | Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a log… | Patch early | 9.8 critical | 68.6% | 2021-02-09 |
| CVE-2017-17736 | Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx an… | Patch early | 9.8 critical | 68.5% | 2018-03-23 |
| CVE-2020-13942 | It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vec… | Patch early | 9.8 critical | 68.3% | 2020-11-24 |
| CVE-2021-29203 | A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software… | Patch early | 9.8 critical | 68.3% | 2021-05-06 |
| CVE-2021-26691 | In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow | Patch early | 9.8 critical | 68.3% | 2021-06-10 |
| CVE-2018-10931 | It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use… | Patch early | 9.8 critical | 68.1% | 2018-08-09 |
| CVE-2018-11714 | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Buil… | Patch early | 9.8 critical | 68.1% | 2018-06-04 |
| CVE-2019-13373 | An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements… | Patch early | 9.8 critical | 68% | 2019-07-06 |
| CVE-2025-40553 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whic… | Patch early | 9.8 critical | 68% | 2026-01-28 |
| CVE-2021-41765 | A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to… | Patch early | 9.8 critical | 67.8% | 2021-11-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt