CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,596 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,728 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-49897 KEV | An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vul… | Patch first | 8.8 high | 50.4% | 2023-12-06 |
| CVE-2013-7331 KEV | The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC s… | Patch first | 6.5 medium | 50.2% | 2014-02-26 |
| CVE-2020-12812 KEV | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succes… | Patch first | 9.8 critical | 49.3% | 2020-07-24 |
| CVE-2021-22017 KEV | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acces… | Patch first | 5.3 medium | 49.2% | 2021-09-23 |
| CVE-2021-3493 KEV | The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files i… | Patch first | 8.8 high | 49.2% | 2021-04-17 |
| CVE-2023-37580 KEV | Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. | Patch first | 6.1 medium | 49.1% | 2023-07-31 |
| CVE-2011-1889 KEV | The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitra… | Patch first | 9.8 critical | 49% | 2011-06-16 |
| CVE-2023-5217 KEV | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exp… | Patch first | 8.8 high | 49% | 2023-09-28 |
| CVE-2015-1671 KEV | The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live… | Patch first | 7.8 high | 49% | 2015-05-13 |
| CVE-2023-28252 KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Patch first | 7.8 high | 49% | 2023-04-11 |
| CVE-2026-85046 KEV | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML… | Patch first | 8.8 high | 48.9% | 2026-09-03 |
| CVE-2025-68645 KEV | A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling o… | Patch first | 8.8 high | 48.9% | 2025-12-22 |
| CVE-2020-9715 KEV | Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-a… | Patch first | 7.8 high | 48.6% | 2020-08-19 |
| CVE-2022-23227 KEV | NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because o… | Patch first | 9.8 critical | 48.5% | 2022-01-14 |
| CVE-2020-16009 KEV | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a craf… | Patch first | 8.8 high | 48.3% | 2020-11-03 |
| CVE-2016-1646 KEV | The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider eleme… | Patch first | 8.8 high | 48.1% | 2016-03-29 |
| CVE-2006-2492 KEV | Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-ass… | Patch first | 8.8 high | 48.1% | 2006-05-20 |
| CVE-2021-26829 KEV | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. | Patch first | 5.4 medium | 48.1% | 2021-06-11 |
| CVE-2021-40407 KEV | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], base… | Patch first | 7.2 high | 47.6% | 2022-01-28 |
| CVE-2023-48365 KEV | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of… | Patch first | 9.6 critical | 47.5% | 2023-11-15 |
| CVE-2026-39808 KEV | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.… | Patch first | 9.8 critical | 47.4% | 2026-04-14 |
| CVE-2021-22893 KEV | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Puls… | Patch first | 10.0 critical | 47.2% | 2021-04-23 |
| CVE-2014-4123 KEV | Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privil… | Patch first | 8.8 high | 47.1% | 2014-10-15 |
| CVE-2022-39197 KEV | An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the C… | Patch first | 6.1 medium | 46.4% | 2022-09-22 |
| CVE-2019-1579 KEV | Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProt… | Patch first | 8.1 high | 46.2% | 2019-07-19 |
| CVE-2024-43573 KEV | Windows MSHTML Platform Spoofing Vulnerability | Patch first | 6.5 medium | 46.1% | 2024-10-08 |
| CVE-2026-12569 KEV | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited th… | Patch first | 9.8 critical | 46% | 2026-06-18 |
| CVE-2026-34910 KEV | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command I… | Patch first | 10.0 critical | 45.8% | 2026-05-22 |
| CVE-2017-6862 KEV | NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and re… | Patch first | 9.8 critical | 45.7% | 2017-05-26 |
| CVE-2017-16651 KEV | Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, in… | Patch first | 7.8 high | 45.7% | 2017-11-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt