CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,759 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,728 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-12231 KEV | A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated… | Patch first | 7.5 high | 7.1% | 2017-09-29 |
| CVE-2017-12233 KEV | Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthent… | Patch first | 7.5 high | 7.1% | 2017-09-29 |
| CVE-2017-12234 KEV | Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthent… | Patch first | 7.5 high | 7.1% | 2017-09-29 |
| CVE-2017-12235 KEV | A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an una… | Patch first | 7.5 high | 7.1% | 2017-09-29 |
| CVE-2017-12237 KEV | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an… | Patch first | 7.5 high | 7.1% | 2017-09-29 |
| CVE-2018-0154 KEV | A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticat… | Patch first | 7.5 high | 7.1% | 2018-03-28 |
| CVE-2026-20128 KEV | A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DC… | Patch first | 7.5 high | 7.1% | 2026-02-25 |
| CVE-2020-6820 KEV | Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild ab… | Patch first | 8.1 high | 7.1% | 2020-04-24 |
| CVE-2026-48710 KEV | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to recon… | Patch first | 6.5 medium | 7.1% | 2026-05-26 |
| CVE-2021-30713 KEV | A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass P… | Patch first | 7.8 high | 7% | 2021-09-08 |
| CVE-2026-19490 KEV | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1… | Patch first | 9.8 critical | 7% | 2026-08-19 |
| CVE-2021-1871 KEV | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update… | Patch first | 9.8 critical | 7% | 2021-04-02 |
| CVE-2021-30952 KEV | An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPa… | Patch first | 7.8 high | 7% | 2021-08-24 |
| CVE-2019-1064 KEV | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfu… | Patch first | 7.8 high | 6.9% | 2019-06-12 |
| CVE-2018-0159 KEV | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could a… | Patch first | 7.5 high | 6.9% | 2018-03-28 |
| CVE-2026-15409 KEV | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacke… | Patch first | 10.0 critical | 6.8% | 2026-07-14 |
| CVE-2023-26369 KEV | Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write v… | Patch first | 7.8 high | 6.7% | 2023-09-13 |
| CVE-2013-1675 KEV | Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initial… | Patch first | 6.5 medium | 6.7% | 2013-05-16 |
| CVE-2022-27518 KEV | Unauthenticated remote arbitrary code execution | Patch first | 9.8 critical | 6.7% | 2022-12-13 |
| CVE-2023-7024 KEV | Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted… | Patch first | 8.8 high | 6.7% | 2023-12-21 |
| CVE-2026-34486 KEV | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.… | Patch first | 7.5 high | 6.6% | 2026-04-09 |
| CVE-2021-33739 KEV | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Patch first | 8.4 high | 6.6% | 2021-06-08 |
| CVE-2021-22600 KEV | A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or d… | Patch first | 6.6 medium | 6.5% | 2022-01-26 |
| CVE-2012-0767 KEV | Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris… | Patch first | 6.1 medium | 6.4% | 2012-02-16 |
| CVE-2025-24990 KEV | Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an… | Patch first | 7.8 high | 6.4% | 2025-10-14 |
| CVE-2020-16010 KEV | Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to po… | Patch first | 9.6 critical | 6.4% | 2020-11-03 |
| CVE-2024-38106 KEV | Windows Kernel Elevation of Privilege Vulnerability | Patch first | 7.0 high | 6.3% | 2024-08-13 |
| CVE-2026-50751 KEV | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote atta… | Patch first | 9.3 critical | 6.3% | 2026-06-08 |
| CVE-2024-38014 KEV | Windows Installer Elevation of Privilege Vulnerability | Patch first | 7.8 high | 6.3% | 2024-09-10 |
| CVE-2020-8468 KEV | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulner… | Patch first | 8.8 high | 6.2% | 2020-03-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt