CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,483 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
36,453 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-9465 KEV | An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as pas… | Patch first | 9.1 critical | 99.6% | 2024-10-09 |
| CVE-2021-33045 KEV | The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentic… | Patch first | 9.8 critical | 99.6% | 2021-09-15 |
| CVE-2020-16846 KEV | An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell… | Patch first | 9.8 critical | 99.6% | 2020-11-06 |
| CVE-2023-20198 KEV | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating… | Patch first | 10.0 critical | 99.6% | 2023-10-16 |
| CVE-2024-4040 KEV | A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote att… | Patch first | 9.8 critical | 99.5% | 2024-04-22 |
| CVE-2022-42475 KEV | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through… | Patch first | 9.8 critical | 99.5% | 2023-01-02 |
| CVE-2025-31324 KEV | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially mal… | Patch first | 10.0 critical | 99.5% | 2025-04-24 |
| CVE-2023-34048 KEV | vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vC… | Patch first | 9.8 critical | 99.4% | 2023-10-25 |
| CVE-2024-38856 KEV | Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to versio… | Patch first | 9.8 critical | 99.4% | 2024-08-05 |
| CVE-2021-32030 KEV | The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass w… | Patch first | 9.8 critical | 99.4% | 2021-05-06 |
| CVE-2022-0543 KEV | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which co… | Patch first | 10.0 critical | 99.4% | 2022-02-18 |
| CVE-2024-4885 KEV | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.Expo… | Patch first | 9.8 critical | 99.3% | 2024-06-25 |
| CVE-2023-28771 KEV | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FL… | Patch first | 9.8 critical | 99.3% | 2023-04-25 |
| CVE-2020-14750 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.… | Patch first | 9.8 critical | 99.3% | 2020-11-02 |
| CVE-2022-24086 KEV | Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checko… | Patch first | 9.8 critical | 99.2% | 2022-02-16 |
| CVE-2023-22515 KEV | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerab… | Patch first | 9.8 critical | 99.2% | 2023-10-04 |
| CVE-2025-68613 KEV | n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remot… | Patch first | 9.9 critical | 99% | 2025-12-19 |
| CVE-2021-40539 KEV | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. | Patch first | 9.8 critical | 99% | 2021-09-07 |
| CVE-2022-3236 KEV | A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older… | Patch first | 9.8 critical | 98.9% | 2022-09-23 |
| CVE-2023-47246 KEV | In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as… | Patch first | 9.8 critical | 98.9% | 2023-11-10 |
| CVE-2025-32433 KEV | Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may… | Patch first | 10.0 critical | 98.8% | 2025-04-16 |
| CVE-2026-1281 KEV | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | Patch first | 9.8 critical | 98.7% | 2026-01-29 |
| CVE-2026-1340 KEV | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | Patch first | 9.8 critical | 98.6% | 2026-01-29 |
| CVE-2024-50623 KEV | In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could l… | Patch first | 9.8 critical | 98.6% | 2024-10-28 |
| CVE-2024-8963 KEV | Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. | Patch first | 9.4 critical | 98.6% | 2024-09-19 |
| CVE-2024-50603 KEV | An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used… | Patch first | 10.0 critical | 98.5% | 2025-01-08 |
| CVE-2025-0108 KEV | An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web inter… | Patch first | 9.1 critical | 98.5% | 2025-02-12 |
| CVE-2023-48788 KEV | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiCl… | Patch first | 9.8 critical | 98.4% | 2024-03-12 |
| CVE-2022-21587 KEV | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are af… | Patch first | 9.8 critical | 98.3% | 2022-10-18 |
| CVE-2018-1000861 KEV | A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main… | Patch first | 9.8 critical | 98.3% | 2018-12-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt