LIVE
NEW KEV CVE-2025-48595 Android Framework · CVSS 8.4|NEW KEV CVE-2022-0492 Linux Kernel · CVSS 7.8|NEW KEV CVE-2024-21182 Oracle WebLogic Server · CVSS 7.5
1645 PATCH NOW 52,738 WATCH +0 24H0 NEW KEVWX ELEVATED 5.5SYNC —
EXPLORE

CVE Explorer

345,926 tracked ·254,375 with full analysis · last sync just now ·API ↗
QUICK
EPSS × CVSS TRIAGE QUADRANT · UPPER-RIGHT = PATCH NOW
BY SEVERITY · 254,375 ANALYZED
EPSS DISTRIBUTION · EXPLOIT PROBABILITY
DISPOSITION FUNNEL254,375 → 1609 patch-now
351,121 results
SORT|1–20 of 351,121
 CVESEVCVSSEPSSKEVDISPOSITIONVENDOR · PRODUCTCWESUMMARYFIXCVE PUBLISHEDWE COVEREDAGE
CVE-2023-23752MED5.3
95%
KEVPATCH NOWJoomla! · Joomla!CWE-284An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.Patch availableFeb 16, 23Jun 2, 261202d
CVE-2017-8917CRIT9.8
95%
PATCH SOONn/a · n/aCWE-89SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.Patch availableMay 17, 17pending3303d
CVE-2018-1000861CRIT9.8
94%
KEVPATCH NOWJenkins · Jenkins Stapler Web FrameworkCWE-502A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoPatch availableDec 10, 18Jun 2, 262731d
CVE-2021-22986CRIT9.8
94%
KEVPATCH NOWF5 · BIG-IP and BIG-IQ Centralized ManagementCWE-918On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST Patch availableMar 31, 21Jun 2, 261889d
CVE-2018-7600CRIT9.8
94%
KEVPATCH NOWDrupal · Drupal CoreCWE-20Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configuraPatch availableMar 29, 18Jun 2, 262987d
CVE-2017-1000353CRIT9.8
94%
KEVPATCH NOWJenkins · JenkinsCWE-502Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a seriaPatch availableJan 29, 18Jun 2, 263046d
CVE-2021-22205CRIT10.0
94%
KEVPATCH NOWGitLab · Community and Enterprise EditionsCWE-94An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.Patch availableApr 23, 21Jun 2, 261866d
CVE-2022-46169CRIT9.8
94%
KEVPATCH NOWCacti · CactiCWE-74Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated usPatch availableDec 5, 22Jun 2, 261275d
CVE-2019-2725CRIT9.8
94%
KEVPATCH NOWOracle · WebLogic ServerCWE-74Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows Patch availableApr 26, 19Jun 2, 262594d
CVE-2024-23897CRIT9.8
94%
KEVPATCH NOWJenkins · Jenkins Command Line Interface (CLI)CWE-22Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticPatch availableJan 24, 24Jun 2, 26860d
CVE-2020-1938CRIT9.8
94%
KEVPATCH NOWApache · TomcatWhen using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If suPatch availableFeb 24, 20Jun 2, 262290d
CVE-2024-6670CRIT9.8
94%
KEVPATCH NOWProgress · WhatsUp GoldIn WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.Patch availableAug 29, 24Jun 2, 26642d
CVE-2019-3396CRIT9.8
94%
KEVPATCH NOWAtlassian · Confluence Server and Data ServerCWE-22The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixedPatch availableMar 25, 19Jun 2, 262626d
CVE-2018-13379CRIT9.1
94%
KEVPATCH NOWFortinet · FortiOSCWE-22An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.Patch availableJun 4, 19Jun 2, 262555d
CVE-2019-17558HIGH7.5
94%
KEVPATCH NOWApache · SolrCWE-74Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or Patch availableDec 30, 19Jun 2, 262346d
CVE-2019-11510CRIT10.0
94%
KEVPATCH NOWIvanti · Pulse Connect SecureCWE-22In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulneraPatch availableMay 8, 19Jun 2, 262582d
CVE-2022-22947CRIT10.0
94%
KEVPATCH NOWVMware · Spring Cloud GatewayCWE-94In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maPatch availableMar 3, 22Jun 2, 261552d
CVE-2022-1388CRIT9.8
94%
KEVPATCH NOWF5 · BIG-IPCWE-306On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iPatch availableMay 5, 22Jun 2, 261489d
CVE-2021-22005CRIT9.8
94%
KEVPATCH NOWVMware · vCenter ServerCWE-22The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server byPatch availableSep 23, 21Jun 2, 261713d
CVE-2022-44877CRIT9.8
94%
KEVPATCH NOWCWP · Control Web PanelCWE-78login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.Jan 5, 23Jun 2, 261244d
/ searchF filterJK next/prev openEPSS bars from FIRST.org · severity from CVSS v3.1 · disposition synthesized from KEV + exploit-maturity + CVSS + EPSS signals