CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,882 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,728 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-9907 KEV | A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application… | Patch first | 7.8 high | 3.2% | 2020-10-16 |
| CVE-2023-6548 KEV | Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP… | Patch first | 5.5 medium | 3.2% | 2024-01-17 |
| CVE-2020-0041 KEV | In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of pr… | Patch first | 7.8 high | 3.1% | 2020-03-10 |
| CVE-2026-87491 KEV | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted… | Patch first | 8.8 high | 3.1% | 2026-09-09 |
| CVE-2017-0001 KEV | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 201… | Patch first | 7.8 high | 3.1% | 2017-03-17 |
| CVE-2021-27562 KEV | In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when ca… | Patch first | 5.5 medium | 3.1% | 2021-05-25 |
| CVE-2021-43226 KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Patch first | 7.8 high | 3.1% | 2021-12-15 |
| CVE-2011-4723 KEV | The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors… | Patch first | 5.7 medium | 3.1% | 2011-12-20 |
| CVE-2023-36584 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 3.1% | 2023-10-10 |
| CVE-2022-41125 KEV | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | Patch first | 7.8 high | 3% | 2022-11-09 |
| CVE-2026-50522 KEV | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | Patch first | 9.8 critical | 3% | 2026-07-14 |
| CVE-2020-6819 KEV | Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the… | Patch first | 8.1 high | 3% | 2020-04-24 |
| CVE-2018-8589 KEV | An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnera… | Patch first | 7.8 high | 3% | 2018-11-14 |
| CVE-2021-30666 KEV | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may… | Patch first | 8.8 high | 3% | 2021-09-08 |
| CVE-2021-29256 KEV | . The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege es… | Patch first | 8.8 high | 3% | 2021-05-24 |
| CVE-2024-32896 KEV | there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pri… | Patch first | 7.8 high | 3% | 2024-06-13 |
| CVE-2021-31199 KEV | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | Patch first | 5.2 medium | 3% | 2021-06-08 |
| CVE-2024-7262 KEV | Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows all… | Patch first | 7.8 high | 2.9% | 2024-08-15 |
| CVE-2024-11667 KEV | A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmwar… | Patch first | 7.5 high | 2.9% | 2024-11-27 |
| CVE-2021-30983 KEV | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to ex… | Patch first | 7.8 high | 2.9% | 2021-08-24 |
| CVE-2023-38606 KEV | This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPad… | Patch first | 5.5 medium | 2.9% | 2023-07-27 |
| CVE-2021-38649 KEV | Open Management Infrastructure Elevation of Privilege Vulnerability | Patch first | 7.0 high | 2.9% | 2021-09-15 |
| CVE-2025-39682 KEV | In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must… | Patch first | 9.8 critical | 2.9% | 2025-09-05 |
| CVE-2021-25337 KEV | Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write… | Patch first | 4.4 medium | 2.8% | 2021-03-04 |
| CVE-2025-61932 KEV | Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing a… | Patch first | 9.8 critical | 2.8% | 2025-10-20 |
| CVE-2025-40602 KEV | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). | Patch first | 6.6 medium | 2.8% | 2025-12-18 |
| CVE-2020-16013 KEV | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a craf… | Patch first | 8.8 high | 2.8% | 2021-01-08 |
| CVE-2020-16017 KEV | Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potenti… | Patch first | 9.6 critical | 2.7% | 2021-01-08 |
| CVE-2021-38645 KEV | Open Management Infrastructure Elevation of Privilege Vulnerability | Patch first | 7.8 high | 2.7% | 2021-09-15 |
| CVE-2022-42948 KEV | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to… | Patch first | 9.8 critical | 2.7% | 2023-03-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt