CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
902 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-0641 KEV | Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary… | Patch first | 7.8 high | 32.3% | 2013-02-14 |
| CVE-2020-8218 KEV | A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution v… | Patch first | 7.2 high | 32.3% | 2020-07-30 |
| CVE-2023-3079 KEV | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… | Patch first | 8.8 high | 32.1% | 2023-06-05 |
| CVE-2017-5070 KEV | Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to ex… | Patch first | 8.8 high | 32.1% | 2017-10-27 |
| CVE-2025-0994 KEV | Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerabili… | Patch first | 8.8 high | 31.3% | 2025-02-06 |
| CVE-2016-4523 KEV | The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bou… | Patch first | 7.5 high | 31.2% | 2016-06-09 |
| CVE-2020-0968 KEV | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin… | Patch first | 7.5 high | 30.7% | 2020-04-15 |
| CVE-2019-13608 KEV | Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks. | Patch first | 7.5 high | 30% | 2019-08-29 |
| CVE-2017-0222 KEV | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vu… | Patch first | 8.8 high | 29.6% | 2017-05-12 |
| CVE-2018-8653 KEV | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engin… | Patch first | 7.5 high | 29.6% | 2018-12-20 |
| CVE-2023-2533 KEV | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an… | Patch first | 8.4 high | 29.2% | 2023-06-20 |
| CVE-2017-0149 KEV | Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft… | Patch first | 8.8 high | 29.2% | 2017-03-17 |
| CVE-2021-30807 KEV | A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watc… | Patch first | 7.8 high | 28.8% | 2021-10-19 |
| CVE-2024-3393 KEV | A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malic… | Patch first | 7.5 high | 28.4% | 2024-12-27 |
| CVE-2022-37969 KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Patch first | 7.8 high | 28.3% | 2022-09-13 |
| CVE-2019-19356 KEV | Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been fou… | Patch first | 7.5 high | 28.2% | 2020-02-07 |
| CVE-2024-1086 KEV | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft… | Patch first | 7.8 high | 28.1% | 2024-01-31 |
| CVE-2023-36802 KEV | Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | Patch first | 7.8 high | 27.9% | 2023-09-12 |
| CVE-2024-21351 KEV | Windows SmartScreen Security Feature Bypass Vulnerability | Patch first | 7.6 high | 27.8% | 2024-02-13 |
| CVE-2025-27363 KEV | An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subg… | Patch first | 8.1 high | 27.8% | 2025-03-11 |
| CVE-2018-8581 KEV | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." Thi… | Patch first | 7.4 high | 27.4% | 2018-11-14 |
| CVE-2023-28205 KEV | A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 a… | Patch first | 8.8 high | 27.1% | 2023-04-10 |
| CVE-2018-4063 KEV | An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially craft… | Patch first | 8.8 high | 27.1% | 2019-05-06 |
| CVE-2024-4978 KEV | Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A rem… | Patch first | 8.4 high | 26.9% | 2024-05-23 |
| CVE-2025-68461 KEV | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. | Patch first | 7.2 high | 26.8% | 2025-12-18 |
| CVE-2014-2817 KEV | Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privil… | Patch first | 8.8 high | 26.3% | 2014-08-12 |
| CVE-2021-22506 KEV | Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The… | Patch first | 7.5 high | 25.7% | 2021-03-26 |
| CVE-2026-20245 KEV | A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Ci… | Patch first | 7.8 high | 25.3% | 2026-06-04 |
| CVE-2016-7855 KEV | Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to e… | Patch first | 8.8 high | 25.2% | 2016-11-01 |
| CVE-2022-0185 KEV | A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel ver… | Patch first | 8.4 high | 25.2% | 2022-02-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt