CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,503 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
450 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-24054 KEV EXP | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | Patch first | 6.5 medium | 58.9% | 2025-03-11 |
| CVE-2017-0101 KEV EXP | The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Ser… | Patch first | 7.8 high | 57.5% | 2017-03-17 |
| CVE-2019-5825 KEV EXP | Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafte… | Patch first | 6.5 medium | 55.9% | 2019-11-25 |
| CVE-2015-1701 KEV EXP | Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a… | Patch first | 7.8 high | 55.9% | 2015-04-21 |
| CVE-2019-11708 KEV EXP | Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent p… | Patch first | 10.0 critical | 55.9% | 2019-07-23 |
| CVE-2026-2441 KEV EXP | Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML… | Patch first | 8.8 high | 55.1% | 2026-02-13 |
| CVE-2016-0984 KEV EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 o… | Patch first | 8.8 high | 54.5% | 2016-02-10 |
| CVE-2019-0541 KEV EXP | A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vu… | Patch first | 8.8 high | 53.2% | 2019-01-08 |
| CVE-2015-2419 KEV EXP | JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption)… | Patch first | 8.8 high | 53.1% | 2015-07-14 |
| CVE-2019-0808 KEV EXP | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation… | Patch first | 7.8 high | 53% | 2019-04-09 |
| CVE-2016-2388 KEV EXP | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP requ… | Patch first | 5.3 medium | 52.2% | 2016-02-16 |
| CVE-2019-13272 KEV EXP | In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptra… | Patch first | 7.8 high | 52.2% | 2019-07-17 |
| CVE-2013-5223 KEV EXP | Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web scr… | Patch first | 5.4 medium | 50.8% | 2013-11-19 |
| CVE-2019-13720 KEV EXP | Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML… | Patch first | 8.8 high | 49.1% | 2019-11-25 |
| CVE-2018-5430 KEV EXP | The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for… | Patch first | 8.8 high | 49% | 2018-04-17 |
| CVE-2014-4404 KEV EXP | Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged conte… | Patch first | 7.8 high | 48.9% | 2014-09-18 |
| CVE-2019-15752 KEV EXP | Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in… | Patch first | 7.8 high | 48.6% | 2019-08-28 |
| CVE-2013-2094 KEV EXP | The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users… | Patch first | 8.4 high | 47.7% | 2013-05-14 |
| CVE-2016-3976 KEV EXP | Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslas… | Patch first | 7.5 high | 47.3% | 2016-04-07 |
| CVE-2019-17026 KEV EXP | Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in t… | Patch first | 8.8 high | 46.3% | 2020-03-02 |
| CVE-2019-0803 KEV EXP | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation… | Patch first | 7.8 high | 45% | 2019-04-09 |
| CVE-2016-3235 KEV EXP | Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which al… | Patch first | 7.8 high | 43.3% | 2016-06-16 |
| CVE-2019-0841 KEV EXP | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of… | Patch first | 7.8 high | 41.4% | 2019-04-09 |
| CVE-2023-29336 KEV EXP | Win32k Elevation of Privilege Vulnerability | Patch first | 7.8 high | 40.9% | 2023-05-09 |
| CVE-2013-6282 KEV EXP | The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, wh… | Patch first | 8.8 high | 39.7% | 2013-11-20 |
| CVE-2013-3660 KEV EXP | The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vi… | Patch first | 7.8 high | 39.3% | 2013-05-24 |
| CVE-2026-39987 KEV EXP | marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks aut… | Patch first | 9.8 critical | 37.9% | 2026-04-09 |
| CVE-2018-13374 KEV EXP | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LD… | Patch first | 4.3 medium | 37.8% | 2019-01-22 |
| CVE-2019-11707 KEV EXP | A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We… | Patch first | 8.8 high | 37.7% | 2019-07-23 |
| CVE-2014-3153 KEV EXP | The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which a… | Patch first | 7.8 high | 37.2% | 2014-06-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt