CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,359 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,624 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-7816 | ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Success… | Patch early | 9.8 critical | 67.8% | 2019-05-24 |
| CVE-2017-18369 | The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function… | Patch early | 9.8 critical | 67.6% | 2019-05-02 |
| CVE-2025-13486 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_f… | Patch early | 9.8 critical | 67.6% | 2025-12-03 |
| CVE-2023-3765 | Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0. | Patch early | 10.0 critical | 67.6% | 2023-07-19 |
| CVE-2023-2732 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verifi… | Patch early | 9.8 critical | 67.5% | 2023-05-25 |
| CVE-2023-34039 | Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor w… | Patch early | 9.8 critical | 67.2% | 2023-08-29 |
| CVE-2022-29806 | ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contribute… | Patch early | 9.8 critical | 67.1% | 2022-04-26 |
| CVE-2020-26935 | An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMy… | Patch early | 9.8 critical | 67.1% | 2020-10-10 |
| CVE-2022-43672 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different softw… | Patch early | 9.8 critical | 67.1% | 2022-11-12 |
| CVE-2024-3552 | The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action av… | Patch early | 9.8 critical | 67.1% | 2024-06-13 |
| CVE-2019-5096 | An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application i… | Patch early | 9.8 critical | 67% | 2019-12-03 |
| CVE-2023-32521 | A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote atta… | Patch early | 9.1 critical | 66.8% | 2023-06-26 |
| CVE-2018-1161 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.2.0.13. Authentication is… | Patch early | 9.8 critical | 66.7% | 2018-02-08 |
| CVE-2021-24321 | The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt… | Patch early | 9.8 critical | 66.6% | 2021-06-01 |
| CVE-2022-23305 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from P… | Patch early | 9.8 critical | 66.5% | 2022-01-18 |
| CVE-2022-3229 | Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated at… | Patch early | 9.8 critical | 66.4% | 2023-02-06 |
| CVE-2023-38204 | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vul… | Patch early | 9.8 critical | 66.2% | 2023-09-14 |
| CVE-2019-6553 | A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in a .dll file of RSLinx Classic… | Patch early | 9.8 critical | 66.1% | 2019-04-04 |
| CVE-2020-26214 | In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to u… | Patch early | 9.1 critical | 65.9% | 2020-11-06 |
| CVE-2020-27130 | A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability i… | Patch early | 9.1 critical | 65.9% | 2020-11-17 |
| CVE-2023-29516 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on `XWiki.Attachmen… | Patch early | 9.9 critical | 65.9% | 2023-04-19 |
| CVE-2019-12630 | A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitra… | Patch early | 9.8 critical | 65.8% | 2019-10-02 |
| CVE-2021-42127 | A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via D… | Patch early | 9.8 critical | 65.8% | 2021-12-07 |
| CVE-2023-30805 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauth… | Patch early | 9.8 critical | 65.8% | 2023-10-10 |
| CVE-2023-30806 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauth… | Patch early | 9.8 critical | 65.8% | 2023-10-10 |
| CVE-2025-8943 | The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inhe… | Patch early | 9.8 critical | 65.8% | 2025-08-14 |
| CVE-2023-25076 | A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc… | Patch early | 9.8 critical | 65.8% | 2023-03-30 |
| CVE-2024-35286 | A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due… | Patch early | 9.8 critical | 65.7% | 2024-10-21 |
| CVE-2020-7471 | Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in… | Patch early | 9.8 critical | 65.6% | 2020-02-03 |
| CVE-2019-10883 | Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection. | Patch early | 9.8 critical | 65.5% | 2019-06-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt