CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,955 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,698 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-45488 | One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virt… | Patch early | 9.8 critical | 50.6% | 2024-08-30 |
| CVE-2023-34124 | The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects G… | Patch early | 9.8 critical | 50.5% | 2023-07-13 |
| CVE-2022-23943 | Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. T… | Patch early | 9.8 critical | 50.4% | 2022-03-14 |
| CVE-2018-8823 | modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.… | Patch early | 9.8 critical | 50.4% | 2018-03-28 |
| CVE-2018-2894 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affe… | Patch early | 9.8 critical | 50.2% | 2018-07-18 |
| CVE-2021-40493 | Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject paramete… | Patch early | 9.8 critical | 50.2% | 2021-10-13 |
| CVE-2017-14078 | SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code… | Patch early | 9.8 critical | 50.2% | 2017-09-22 |
| CVE-2023-44351 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could… | Patch early | 9.8 critical | 50.2% | 2023-11-17 |
| CVE-2018-14364 | GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and r… | Patch early | 9.8 critical | 50.1% | 2018-07-18 |
| CVE-2023-1133 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ U… | Patch early | 9.8 critical | 50.1% | 2023-03-27 |
| CVE-2024-33610 | "sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session informat… | Patch early | 9.1 critical | 50% | 2024-11-26 |
| CVE-2022-24260 | A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level. | Patch early | 9.8 critical | 50% | 2022-02-04 |
| CVE-2025-49002 | DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-… | Patch early | 9.8 critical | 50% | 2025-06-03 |
| CVE-2016-5118 | The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) chara… | Patch early | 9.8 critical | 50% | 2016-06-10 |
| CVE-2018-16159 | The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front… | Patch early | 9.8 critical | 49.9% | 2018-08-30 |
| CVE-2024-8275 | The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all ve… | Patch early | 9.8 critical | 49.9% | 2024-09-25 |
| CVE-2023-46347 | In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injecti… | Patch early | 9.8 critical | 49.9% | 2023-10-25 |
| CVE-2020-36239 | Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17… | Patch early | 9.8 critical | 49.8% | 2021-07-29 |
| CVE-2020-13756 | Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or ge… | Patch early | 9.8 critical | 49.8% | 2020-06-03 |
| CVE-2018-15439 | A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechan… | Patch early | 9.8 critical | 49.7% | 2018-11-08 |
| CVE-2017-17485 | FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CV… | Patch early | 9.8 critical | 49.7% | 2018-01-10 |
| CVE-2019-0785 | A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server… | Patch early | 9.8 critical | 49.6% | 2019-07-15 |
| CVE-2022-22956 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious a… | Patch early | 9.8 critical | 49.5% | 2022-04-13 |
| CVE-2023-31546 | Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature. | Patch early | 9.6 critical | 49.4% | 2023-12-14 |
| CVE-2019-17570 | An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library… | Patch early | 9.8 critical | 49.3% | 2020-01-23 |
| CVE-2022-24760 | Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Serv… | Patch early | 10.0 critical | 49.1% | 2022-03-12 |
| CVE-2024-46909 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context… | Patch early | 9.8 critical | 48.9% | 2024-12-02 |
| CVE-2020-11998 | A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map t… | Patch early | 9.8 critical | 48.9% | 2020-09-10 |
| CVE-2023-3959 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vuln… | Patch early | 9.8 critical | 48.8% | 2023-11-08 |
| CVE-2023-26802 | An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication… | Patch early | 9.8 critical | 48.7% | 2023-03-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt