CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,648 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,728 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-32435 KEV | A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16… | Patch first | 8.8 high | 23% | 2023-06-23 |
| CVE-2022-0609 KEV | Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM… | Patch first | 8.8 high | 22.9% | 2022-04-05 |
| CVE-2021-22899 KEV | A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code executi… | Patch first | 8.8 high | 22.9% | 2021-05-27 |
| CVE-2024-44309 KEV | A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1… | Patch first | 6.3 medium | 22.6% | 2024-11-20 |
| CVE-2024-37079 KEV | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter S… | Patch first | 9.8 critical | 22.4% | 2024-06-18 |
| CVE-2017-0210 KEV | An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker t… | Patch first | 8.8 high | 22.3% | 2017-04-12 |
| CVE-2014-0546 KEV | Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and conseque… | Patch first | 9.8 critical | 22.3% | 2014-08-12 |
| CVE-2025-14174 KEV | Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access… | Patch first | 8.8 high | 22.3% | 2025-12-12 |
| CVE-2016-1019 KEV | Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code… | Patch first | 9.8 critical | 22.3% | 2016-04-07 |
| CVE-2021-31956 KEV | Windows NTFS Elevation of Privilege Vulnerability | Patch first | 7.8 high | 22.3% | 2021-06-08 |
| CVE-2018-8639 KEV | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation… | Patch first | 7.8 high | 22.2% | 2018-12-12 |
| CVE-2025-54948 KEV | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and e… | Patch first | 9.4 critical | 22% | 2025-08-05 |
| CVE-2016-0162 KEV | Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explor… | Patch first | 4.3 medium | 22% | 2016-04-12 |
| CVE-2020-27930 KEV | A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS… | Patch first | 7.8 high | 22% | 2020-12-08 |
| CVE-2025-43300 KEV | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS… | Patch first | 10.0 critical | 22% | 2025-08-21 |
| CVE-2021-34484 KEV | Windows User Profile Service Elevation of Privilege Vulnerability | Patch first | 7.8 high | 21.8% | 2021-08-12 |
| CVE-2019-1297 KEV | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft… | Patch first | 8.8 high | 21.8% | 2019-09-11 |
| CVE-2025-23209 KEV | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerabi… | Patch first | 8.0 high | 21.8% | 2025-01-18 |
| CVE-2019-0903 KEV | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remo… | Patch first | 8.8 high | 21.7% | 2019-05-16 |
| CVE-2023-29360 KEV | Microsoft Streaming Service Elevation of Privilege Vulnerability | Patch first | 8.4 high | 21.6% | 2023-06-14 |
| CVE-2024-40891 KEV | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10… | Patch first | 8.8 high | 21.5% | 2025-02-04 |
| CVE-2018-19943 KEV | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in th… | Patch first | 8.0 high | 21.5% | 2020-10-28 |
| CVE-2017-6742 KEV | A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely ex… | Patch first | 8.8 high | 21.4% | 2017-07-17 |
| CVE-2020-9377 KEV | D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no… | Patch first | 8.8 high | 21.3% | 2020-07-09 |
| CVE-2009-1862 KEV | Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, all… | Patch first | 7.8 high | 21.2% | 2009-07-23 |
| CVE-2012-5054 KEV | Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitr… | Patch first | 8.8 high | 21.2% | 2012-09-24 |
| CVE-2024-7971 KEV | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium s… | Patch first | 9.6 critical | 21.1% | 2024-08-21 |
| CVE-2012-1854 KEV | Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Appl… | Patch first | 7.8 high | 21% | 2012-07-10 |
| CVE-2014-9163 KEV | Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on… | Patch first | 7.8 high | 20.7% | 2014-12-10 |
| CVE-2023-36563 KEV | Microsoft WordPad Information Disclosure Vulnerability | Patch first | 6.5 medium | 20.7% | 2023-10-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt