CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,014 CVEs
1,733 on KEV
17,286 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
36,699 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-30080 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Patch early | 9.8 critical | 43.1% | 2024-06-11 |
| CVE-2022-1281 | The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, makin… | Patch early | 9.8 critical | 43.1% | 2022-05-02 |
| CVE-2023-49231 | An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API t… | Patch early | 9.8 critical | 42.9% | 2024-03-29 |
| CVE-2025-64155 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3… | Patch early | 9.8 critical | 42.8% | 2026-01-13 |
| CVE-2021-43421 | A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arb… | Patch early | 9.8 critical | 42.8% | 2022-04-07 |
| CVE-2023-25826 | Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameter… | Patch early | 9.8 critical | 42.8% | 2023-05-03 |
| CVE-2022-4060 | The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors… | Patch early | 9.8 critical | 42.7% | 2023-01-16 |
| CVE-2017-11283 | Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 an… | Patch early | 9.8 critical | 42.7% | 2017-12-01 |
| CVE-2017-11284 | Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 an… | Patch early | 9.8 critical | 42.7% | 2017-12-01 |
| CVE-2022-42233 | Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability. | Patch early | 9.8 critical | 42.7% | 2022-10-20 |
| CVE-2022-35710 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could re… | Patch early | 9.8 critical | 42.6% | 2022-10-14 |
| CVE-2019-12987 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6). | Patch early | 9.8 critical | 42.6% | 2019-07-16 |
| CVE-2019-12988 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6). | Patch early | 9.8 critical | 42.6% | 2019-07-16 |
| CVE-2023-2986 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is… | Patch early | 9.8 critical | 42.5% | 2023-06-08 |
| CVE-2023-41887 | OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any… | Patch early | 9.8 critical | 42.5% | 2023-09-15 |
| CVE-2019-13132 | In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, runnin… | Patch early | 9.8 critical | 42.5% | 2019-07-10 |
| CVE-2025-68615 | net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd d… | Patch early | 9.8 critical | 42.4% | 2025-12-23 |
| CVE-2022-2234 | An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system. | Patch early | 9.9 critical | 42.3% | 2022-08-24 |
| CVE-2009-2494 | The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and S… | Patch early | 9.8 critical | 42.3% | 2009-08-12 |
| CVE-2025-30220 | GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent… | Patch early | 9.9 critical | 42.3% | 2025-06-10 |
| CVE-2024-45387 | An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "… | Patch early | 9.9 critical | 42.2% | 2024-12-23 |
| CVE-2023-28662 | The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the t… | Patch early | 9.8 critical | 42.2% | 2023-03-22 |
| CVE-2022-34267 | An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbi… | Patch early | 9.8 critical | 42.2% | 2023-12-25 |
| CVE-2021-24284 | The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The sup… | Patch early | 9.8 critical | 42.1% | 2021-05-14 |
| CVE-2021-37580 | A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affe… | Patch early | 9.8 critical | 41.9% | 2021-11-16 |
| CVE-2024-25153 | A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’… | Patch early | 9.8 critical | 41.7% | 2024-03-13 |
| CVE-2022-22721 | If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later cau… | Patch early | 9.1 critical | 41.7% | 2022-03-14 |
| CVE-2020-3331 | A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an un… | Patch early | 9.8 critical | 41.7% | 2020-07-16 |
| CVE-2016-7479 | In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free.… | Patch early | 9.8 critical | 41.7% | 2017-01-12 |
| CVE-2019-19307 | An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause a… | Patch early | 9.8 critical | 41.6% | 2019-11-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt