CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
615 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-20753 KEV | Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads… | Patch first | 9.8 critical | 29.3% | 2019-02-05 |
| CVE-2014-3931 KEV | fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption. | Patch first | 9.8 critical | 29% | 2017-03-31 |
| CVE-2023-33010 KEV | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmwar… | Patch first | 9.8 critical | 28.8% | 2023-05-24 |
| CVE-2018-19949 KEV | If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the fol… | Patch first | 9.8 critical | 28.4% | 2020-10-28 |
| CVE-2024-11120 KEV | Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject an… | Patch first | 9.8 critical | 28.4% | 2024-11-15 |
| CVE-2026-76461 KEV | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execu… | Patch first | 9.8 critical | 28.3% | 2026-09-14 |
| CVE-2023-33009 KEV | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware… | Patch first | 9.8 critical | 28.1% | 2023-05-24 |
| CVE-2020-5135 KEV | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending… | Patch first | 9.8 critical | 26.9% | 2020-10-12 |
| CVE-2025-14733 KEV | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code.… | Patch first | 9.8 critical | 26.5% | 2025-12-19 |
| CVE-2015-2590 KEV | Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality… | Patch first | 9.8 critical | 25.5% | 2015-07-16 |
| CVE-2025-4632 KEV | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to wri… | Patch first | 9.8 critical | 24.3% | 2025-05-13 |
| CVE-2026-60004 KEV | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. | Patch first | 9.8 critical | 24% | 2026-08-26 |
| CVE-2025-23006 KEV | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central M… | Patch first | 9.8 critical | 23.4% | 2025-01-23 |
| CVE-2024-9680 KEV | An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of th… | Patch first | 9.8 critical | 23.2% | 2024-10-09 |
| CVE-2024-37079 KEV | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter S… | Patch first | 9.8 critical | 22.4% | 2024-06-18 |
| CVE-2014-0546 KEV | Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and conseque… | Patch first | 9.8 critical | 22.3% | 2014-08-12 |
| CVE-2016-1019 KEV | Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code… | Patch first | 9.8 critical | 22.3% | 2016-04-07 |
| CVE-2025-54948 KEV | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and e… | Patch first | 9.4 critical | 22% | 2025-08-05 |
| CVE-2025-43300 KEV | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS… | Patch first | 10.0 critical | 22% | 2025-08-21 |
| CVE-2024-7971 KEV | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium s… | Patch first | 9.6 critical | 21.1% | 2024-08-21 |
| CVE-2026-48939 KEV | A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP… | Patch first | 9.8 critical | 20.1% | 2026-06-20 |
| CVE-2016-4171 KEV | Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as explo… | Patch first | 9.8 critical | 20.1% | 2016-06-16 |
| CVE-2026-93616 KEV | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Manageme… | Patch first | 9.8 critical | 19.7% | 2026-09-22 |
| CVE-2025-7775 KEV | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is confi… | Patch first | 9.8 critical | 19.6% | 2025-08-26 |
| CVE-2022-26871 KEV | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which co… | Patch first | 9.8 critical | 19.5% | 2022-03-29 |
| CVE-2025-67038 KEV | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. T… | Patch first | 9.8 critical | 19.3% | 2026-03-11 |
| CVE-2016-7836 KEV | SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the manag… | Patch first | 9.8 critical | 19.2% | 2017-06-09 |
| CVE-2026-72898 KEV | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access t… | Patch first | 10.0 critical | 19% | 2026-08-10 |
| CVE-2026-9586 KEV | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning… | Patch first | 9.8 critical | 19% | 2026-07-17 |
| CVE-2015-5123 KEV | Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windo… | Patch first | 9.8 critical | 18.8% | 2015-07-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt