CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,424 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-26
36,450 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-44228 KEV EXP | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and… | Patch first | 10.0 critical | 100% | 2021-12-10 |
| CVE-2019-11510 KEV EXP | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can sen… | Patch first | 10.0 critical | 100% | 2019-05-08 |
| CVE-2024-3400 KEV EXP | A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specif… | Patch first | 10.0 critical | 100% | 2024-04-12 |
| CVE-2019-0708 KEV EXP | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects… | Patch first | 9.8 critical | 100% | 2019-05-16 |
| CVE-2023-27350 KEV EXP | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is n… | Patch first | 9.8 critical | 100% | 2023-04-20 |
| CVE-2023-1671 KEV EXP | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitra… | Patch first | 9.8 critical | 100% | 2023-04-04 |
| CVE-2014-6271 KEV EXP | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to ex… | Patch first | 9.8 critical | 100% | 2014-09-24 |
| CVE-2020-5902 KEV EXP | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMU… | Patch first | 9.8 critical | 100% | 2020-07-01 |
| CVE-2021-35464 KEV EXP | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not… | Patch first | 9.8 critical | 100% | 2021-07-22 |
| CVE-2017-9841 KEV EXP | Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginni… | Patch first | 9.8 critical | 100% | 2017-06-27 |
| CVE-2024-23897 KEV EXP | Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a f… | Patch first | 9.8 critical | 100% | 2024-01-24 |
| CVE-2019-19781 KEV EXP | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal. | Patch first | 9.8 critical | 100% | 2019-12-27 |
| CVE-2017-5638 KEV EXP | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message gener… | Patch first | 9.8 critical | 100% | 2017-03-11 |
| CVE-2021-26084 KEV EXP | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to exec… | Patch first | 9.8 critical | 100% | 2021-08-30 |
| CVE-2022-26134 KEV EXP | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to exec… | Patch first | 9.8 critical | 100% | 2022-06-03 |
| CVE-2015-1635 KEV EXP | HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers t… | Patch first | 9.8 critical | 100% | 2015-04-14 |
| CVE-2018-13379 KEV EXP | An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.… | Patch first | 9.1 critical | 100% | 2019-06-04 |
| CVE-2013-2251 KEV EXP | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redir… | Patch first | 9.8 critical | 100% | 2013-07-20 |
| CVE-2012-1823 KEV EXP | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings… | Patch first | 9.8 critical | 100% | 2012-05-11 |
| CVE-2025-53770 KEV EXP | Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft… | Patch first | 9.8 critical | 100% | 2025-07-20 |
| CVE-2020-14882 KEV EXP | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.… | Patch first | 9.8 critical | 100% | 2020-10-21 |
| CVE-2021-26855 KEV EXP | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch first | 9.1 critical | 100% | 2021-03-03 |
| CVE-2022-44877 KEV EXP | login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via sh… | Patch first | 9.8 critical | 100% | 2023-01-05 |
| CVE-2020-8515 KEV EXP | DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root… | Patch first | 9.8 critical | 100% | 2020-02-01 |
| CVE-2025-3248 KEV EXP | Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can s… | Patch first | 9.8 critical | 100% | 2025-04-07 |
| CVE-2021-41773 KEV EXP | A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fil… | Patch first | 9.8 critical | 100% | 2021-10-05 |
| CVE-2018-7600 KEV EXP | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue… | Patch first | 9.8 critical | 100% | 2018-03-29 |
| CVE-2023-42793 KEV EXP | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible | Patch first | 9.8 critical | 100% | 2023-09-19 |
| CVE-2024-4577 KEV EXP | In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use… | Patch first | 9.8 critical | 100% | 2024-06-09 |
| CVE-2019-9670 KEV EXP | mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstra… | Patch first | 9.8 critical | 100% | 2019-05-29 |
page 1 of 334
next →
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt