CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,503 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
902 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-11826 KEV | Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer,… | Patch first | 7.8 high | 81.2% | 2017-10-13 |
| CVE-2017-0262 KEV | Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle obj… | Patch first | 7.8 high | 81% | 2017-05-12 |
| CVE-2021-26411 KEV | Internet Explorer Memory Corruption Vulnerability | Patch first | 8.8 high | 80.8% | 2021-03-11 |
| CVE-2023-22952 KEV | In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. | Patch first | 8.8 high | 80.1% | 2023-01-11 |
| CVE-2013-1331 KEV | Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Offi… | Patch first | 7.8 high | 79.8% | 2013-06-12 |
| CVE-2024-8957 KEV | PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_ad… | Patch first | 7.2 high | 79.7% | 2024-09-17 |
| CVE-2021-1732 KEV | Windows Win32k Elevation of Privilege Vulnerability | Patch first | 7.8 high | 78.4% | 2021-02-25 |
| CVE-2021-21975 KEV | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vR… | Patch first | 7.5 high | 78.3% | 2021-03-31 |
| CVE-2011-3402 KEV | Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Se… | Patch first | 8.8 high | 78.1% | 2011-11-04 |
| CVE-2017-0261 KEV | Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle obj… | Patch first | 7.8 high | 78.1% | 2017-05-12 |
| CVE-2023-27351 KEV | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is n… | Patch first | 7.5 high | 78.1% | 2023-04-20 |
| CVE-2025-6204 KEV | An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an… | Patch first | 8.0 high | 78% | 2025-08-04 |
| CVE-2022-41080 KEV | Microsoft Exchange Server Elevation of Privilege Vulnerability | Patch first | 8.8 high | 77.3% | 2022-11-09 |
| CVE-2021-42287 KEV | Active Directory Domain Services Elevation of Privilege Vulnerability | Patch first | 7.5 high | 77.2% | 2021-11-10 |
| CVE-2021-38406 KEV | Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could r… | Patch first | 7.8 high | 76.4% | 2021-09-17 |
| CVE-2023-44221 KEV | Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative priv… | Patch first | 7.2 high | 76.3% | 2023-12-05 |
| CVE-2021-30860 KEV | An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8,… | Patch first | 7.8 high | 76% | 2021-08-24 |
| CVE-2021-25298 KEV | Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/c… | Patch first | 8.8 high | 75.1% | 2021-02-15 |
| CVE-2024-21182 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.… | Patch first | 7.5 high | 74.2% | 2024-07-16 |
| CVE-2021-40449 KEV | Win32k Elevation of Privilege Vulnerability | Patch first | 7.8 high | 74.1% | 2021-10-13 |
| CVE-2018-8414 KEV | A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vu… | Patch first | 8.8 high | 74% | 2018-08-15 |
| CVE-2025-40536 KEV | SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated atta… | Patch first | 8.1 high | 73.6% | 2026-01-28 |
| CVE-2021-42278 KEV | Active Directory Domain Services Elevation of Privilege Vulnerability | Patch first | 7.5 high | 73.3% | 2021-11-10 |
| CVE-2023-47565 KEV | An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerabilit… | Patch first | 8.0 high | 73.3% | 2023-12-08 |
| CVE-2020-5741 KEV | Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code. | Patch first | 7.2 high | 72.9% | 2020-05-08 |
| CVE-2026-21509 KEV | Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. | Patch first | 7.8 high | 72.9% | 2026-01-26 |
| CVE-2021-25296 KEV | Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/w… | Patch first | 8.8 high | 72.2% | 2021-02-15 |
| CVE-2025-30066 KEV | tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on… | Patch first | 8.6 high | 72.1% | 2025-03-15 |
| CVE-2012-1856 KEV | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and… | Patch first | 8.8 high | 72% | 2012-08-15 |
| CVE-2020-3259 KEV | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co… | Patch first | 7.5 high | 71.8% | 2020-05-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt