CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,529 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
615 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-22224 KEV | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with l… | Patch first | 9.3 critical | 1.6% | 2025-03-04 |
| CVE-2026-72529 KEV | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, a… | Patch first | 9.8 critical | 1.5% | 2026-08-19 |
| CVE-2026-48027 KEV | Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed… | Patch first | 9.8 critical | 1.3% | 2026-05-27 |
| CVE-2026-65400 KEV | An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma… | Patch first | 9.8 critical | 1.2% | 2026-08-06 |
| CVE-2025-59374 KEV | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supp… | Patch first | 9.8 critical | 1.2% | 2025-12-17 |
| CVE-2026-45321 KEV | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The… | Patch first | 9.6 critical | 1.1% | 2026-05-12 |
| CVE-2026-48172 KEV | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best… | Patch first | 9.8 critical | 1% | 2026-05-21 |
| CVE-2026-8452 KEV | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the applianc… | Patch first | 9.8 critical | 1% | 2026-06-30 |
| CVE-2026-16812 KEV | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and… | Patch first | 10.0 critical | 1% | 2026-07-27 |
| CVE-2026-85102 KEV | Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to e… | Patch first | 9.8 critical | 1% | 2026-09-09 |
| CVE-2026-8398 KEV | A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distribu… | Patch first | 9.8 critical | 1% | 2026-05-15 |
| CVE-2026-84869 KEV | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host… | Patch first | 9.9 critical | 0.9% | 2026-09-08 |
| CVE-2026-93952 KEV | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and… | Patch first | 10.0 critical | 0.9% | 2026-09-22 |
| CVE-2026-46817 KEV | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2… | Patch first | 9.8 critical | 0.8% | 2026-05-28 |
| CVE-2026-5430 KEV | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to… | Patch first | 10.0 critical | 0.6% | 2026-08-06 |
← previous page 21 of 21
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt