CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,405 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
36,642 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-42627 | The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to d… | Patch early | 9.8 critical | 63.1% | 2022-08-23 |
| CVE-2018-3191 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… | Patch early | 9.8 critical | 62.9% | 2018-10-17 |
| CVE-2016-0638 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attacke… | Patch early | 9.8 critical | 62.9% | 2016-04-21 |
| CVE-2019-0698 | A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows… | Patch early | 9.8 critical | 62.9% | 2019-04-09 |
| CVE-2014-2323 | SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name… | Patch early | 9.8 critical | 62.8% | 2014-03-14 |
| CVE-2019-11500 | In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs beca… | Patch early | 9.8 critical | 62.6% | 2019-08-29 |
| CVE-2017-3191 | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote atta… | Patch early | 9.8 critical | 62.5% | 2017-12-16 |
| CVE-2011-0657 | DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R… | Patch early | 9.8 critical | 62.5% | 2011-04-13 |
| CVE-2022-25772 | A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascrip… | Patch early | 9.6 critical | 62.3% | 2022-06-20 |
| CVE-2023-35166 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content wit… | Patch early | 9.9 critical | 62.2% | 2023-06-20 |
| CVE-2023-28503 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authen… | Patch early | 9.8 critical | 62.1% | 2023-03-29 |
| CVE-2024-46506 | NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an au… | Patch early | 10.0 critical | 62% | 2025-05-13 |
| CVE-2017-7546 | PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain a… | Patch early | 9.8 critical | 61.6% | 2017-08-16 |
| CVE-2021-27670 | Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter. | Patch early | 9.8 critical | 61.3% | 2021-02-25 |
| CVE-2021-26424 | Windows TCP/IP Remote Code Execution Vulnerability | Patch early | 9.9 critical | 61.1% | 2021-08-12 |
| CVE-2023-28502 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-b… | Patch early | 9.8 critical | 61.1% | 2023-03-29 |
| CVE-2023-31446 | In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads… | Patch early | 9.8 critical | 61.1% | 2024-01-10 |
| CVE-2020-3250 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authe… | Patch early | 9.8 critical | 60.9% | 2020-04-15 |
| CVE-2021-30181 | Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are u… | Patch early | 9.8 critical | 60.9% | 2021-06-01 |
| CVE-2017-14942 | Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-… | Patch early | 9.8 critical | 60.9% | 2017-09-30 |
| CVE-2025-40554 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke s… | Patch early | 9.8 critical | 60.6% | 2026-01-28 |
| CVE-2024-48914 | Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an at… | Patch early | 9.1 critical | 60.4% | 2024-10-15 |
| CVE-2021-20078 | Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway… | Patch early | 9.1 critical | 60.4% | 2021-04-01 |
| CVE-2021-30118 | An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and s… | Patch early | 9.8 critical | 60.3% | 2021-07-09 |
| CVE-2025-11833 | The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data d… | Patch early | 9.8 critical | 60.3% | 2025-11-01 |
| CVE-2022-35869 | This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). A… | Patch early | 9.8 critical | 60.3% | 2022-07-25 |
| CVE-2021-30180 | Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the cus… | Patch early | 9.8 critical | 60.3% | 2021-06-01 |
| CVE-2022-29775 | iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL. | Patch early | 9.8 critical | 60.3% | 2022-06-21 |
| CVE-2023-29919 | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricte… | Patch early | 9.1 critical | 60.2% | 2023-05-23 |
| CVE-2026-19478 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 befo… | Patch early | 9.4 critical | 60.2% | 2026-08-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt