CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,482 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
36,453 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-1709 KEV | ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allo… | Patch first | 10.0 critical | 100% | 2024-02-21 |
| CVE-2025-59287 KEV | Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | Patch first | 9.8 critical | 100% | 2025-10-14 |
| CVE-2021-45046 KEV | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows att… | Patch first | 9.0 critical | 100% | 2021-12-14 |
| CVE-2020-25506 KEV | D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execu… | Patch first | 9.8 critical | 100% | 2021-02-02 |
| CVE-2024-38475 KEV | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are pe… | Patch first | 9.1 critical | 100% | 2024-07-01 |
| CVE-2023-38035 KEV | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authenticat… | Patch first | 9.8 critical | 100% | 2023-08-21 |
| CVE-2023-34362 KEV | In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection… | Patch first | 9.8 critical | 99.9% | 2023-06-02 |
| CVE-2021-38647 KEV | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | Patch first | 9.8 critical | 99.9% | 2021-09-15 |
| CVE-2021-39226 KEV | Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with… | Patch first | 9.8 critical | 99.9% | 2021-10-05 |
| CVE-2021-1497 KEV | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform comman… | Patch first | 9.8 critical | 99.9% | 2021-05-06 |
| CVE-2022-35405 KEV | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects… | Patch first | 9.8 critical | 99.9% | 2022-07-19 |
| CVE-2026-10520 KEV | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achiev… | Patch first | 10.0 critical | 99.9% | 2026-06-09 |
| CVE-2021-20038 KEV | A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attac… | Patch first | 9.8 critical | 99.9% | 2021-12-08 |
| CVE-2022-24816 KEV | JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network… | Patch first | 10.0 critical | 99.9% | 2022-04-13 |
| CVE-2024-45519 KEV | The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 someti… | Patch first | 10.0 critical | 99.9% | 2024-10-02 |
| CVE-2023-46604 KEV | The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to… | Patch first | 10.0 critical | 99.9% | 2023-10-27 |
| CVE-2021-44515 KEV | Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in… | Patch first | 9.8 critical | 99.9% | 2021-12-12 |
| CVE-2021-35394 KEV | Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binar… | Patch first | 9.8 critical | 99.9% | 2021-08-16 |
| CVE-2024-0012 KEV | An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface… | Patch first | 9.8 critical | 99.8% | 2024-11-18 |
| CVE-2021-37415 KEV | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. | Patch first | 9.8 critical | 99.8% | 2021-09-01 |
| CVE-2024-36401 KEV | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple… | Patch first | 9.8 critical | 99.8% | 2024-07-01 |
| CVE-2025-10035 KEV | A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to… | Patch first | 10.0 critical | 99.8% | 2025-09-18 |
| CVE-2021-31166 KEV | HTTP Protocol Stack Remote Code Execution Vulnerability | Patch first | 9.8 critical | 99.8% | 2021-05-11 |
| CVE-2022-47966 KEV | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xml… | Patch first | 9.8 critical | 99.8% | 2023-01-18 |
| CVE-2023-3519 KEV | Unauthenticated remote code execution | Patch first | 9.8 critical | 99.7% | 2023-07-19 |
| CVE-2020-15505 KEV | A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0,… | Patch first | 9.8 critical | 99.7% | 2020-07-07 |
| CVE-2025-61882 KEV | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that a… | Patch first | 9.8 critical | 99.7% | 2025-10-05 |
| CVE-2025-48703 KEV | CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total… | Patch first | 9.0 critical | 99.7% | 2025-09-19 |
| CVE-2022-22965 KEV | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit r… | Patch first | 9.8 critical | 99.6% | 2022-04-01 |
| CVE-2024-5217 KEV | ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. Thi… | Patch first | 9.8 critical | 99.6% | 2024-07-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt