CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,528 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
615 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-63030 KEV | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__no… | Patch first | 9.8 critical | 10.1% | 2026-07-17 |
| CVE-2024-6047 KEV | Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vul… | Patch first | 9.8 critical | 10.1% | 2024-06-17 |
| CVE-2026-64849 KEV | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated… | Patch first | 9.3 critical | 9.8% | 2026-08-17 |
| CVE-2026-63077 KEV | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | Patch first | 9.8 critical | 9.8% | 2026-07-27 |
| CVE-2022-20701 KEV | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch first | 10.0 critical | 9.7% | 2022-02-10 |
| CVE-2026-35273 KEV | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions th… | Patch first | 9.8 critical | 9.4% | 2026-06-11 |
| CVE-2022-20703 KEV | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch first | 10.0 critical | 9.2% | 2022-02-10 |
| CVE-2026-35616 KEV | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized c… | Patch first | 9.8 critical | 9.1% | 2026-04-04 |
| CVE-2026-83548 KEV | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unau… | Patch first | 10.0 critical | 8.8% | 2026-09-01 |
| CVE-2018-14558 KEV | An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9),… | Patch first | 9.8 critical | 8.7% | 2018-10-30 |
| CVE-2024-4671 KEV | Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially p… | Patch first | 9.6 critical | 8.3% | 2024-05-14 |
| CVE-2019-11634 KEV | Citrix Workspace App before 1904 for Windows has Incorrect Access Control. | Patch first | 9.8 critical | 8% | 2019-05-22 |
| CVE-2018-19323 KEV | The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GUR… | Patch first | 9.8 critical | 7.8% | 2018-12-21 |
| CVE-2012-1710 KEV | Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect c… | Patch first | 9.8 critical | 7.8% | 2012-05-03 |
| CVE-2021-1870 KEV | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update… | Patch first | 9.8 critical | 7.7% | 2021-04-02 |
| CVE-2024-5274 KEV | Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML… | Patch first | 9.6 critical | 7.5% | 2024-05-28 |
| CVE-2020-1040 KEV | A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user o… | Patch first | 9.0 critical | 7.4% | 2020-07-14 |
| CVE-2019-0344 KEV | Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to exe… | Patch first | 9.8 critical | 7.1% | 2019-08-14 |
| CVE-2026-19490 KEV | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1… | Patch first | 9.8 critical | 7% | 2026-08-19 |
| CVE-2021-1871 KEV | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update… | Patch first | 9.8 critical | 7% | 2021-04-02 |
| CVE-2026-15409 KEV | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacke… | Patch first | 10.0 critical | 6.8% | 2026-07-14 |
| CVE-2022-27518 KEV | Unauthenticated remote arbitrary code execution | Patch first | 9.8 critical | 6.7% | 2022-12-13 |
| CVE-2020-16010 KEV | Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to po… | Patch first | 9.6 critical | 6.4% | 2020-11-03 |
| CVE-2026-50751 KEV | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote atta… | Patch first | 9.3 critical | 6.3% | 2026-06-08 |
| CVE-2021-27101 KEV | Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA… | Patch first | 9.8 critical | 6% | 2021-02-16 |
| CVE-2026-42208 KEV | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query… | Patch first | 9.8 critical | 5.8% | 2026-05-08 |
| CVE-2022-3075 KEV | Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to po… | Patch first | 9.6 critical | 5.8% | 2022-09-26 |
| CVE-2023-2136 KEV | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially pe… | Patch first | 9.6 critical | 5.7% | 2023-04-19 |
| CVE-2026-48558 KEV | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When… | Patch first | 10.0 critical | 5.7% | 2026-06-12 |
| CVE-2022-20700 KEV | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch first | 10.0 critical | 5.7% | 2022-02-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt