CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,482 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
902 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-0185 KEV EXP | Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Cent… | Patch first | 7.8 high | 69.8% | 2016-05-11 |
| CVE-2013-1690 KEV EXP | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle… | Patch first | 8.8 high | 69% | 2013-06-26 |
| CVE-2015-4495 KEV EXP | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same… | Patch first | 8.8 high | 68.6% | 2015-08-08 |
| CVE-2019-18426 KEV EXP | A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site script… | Patch first | 8.2 high | 67.9% | 2020-01-21 |
| CVE-2016-4657 KEV EXP | WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web… | Patch first | 8.8 high | 66.8% | 2016-08-25 |
| CVE-2013-0629 KEV EXP | Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vecto… | Patch first | 7.5 high | 65.8% | 2013-01-09 |
| CVE-2015-7645 KEV EXP | Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attack… | Patch first | 7.8 high | 65.3% | 2015-10-15 |
| CVE-2019-0211 KEV EXP | In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (… | Patch first | 7.8 high | 65% | 2019-04-08 |
| CVE-2011-0609 KEV EXP | Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android;… | Patch first | 7.8 high | 63.5% | 2011-03-15 |
| CVE-2016-0151 KEV EXP | The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 m… | Patch first | 7.8 high | 62.9% | 2016-04-12 |
| CVE-2018-6065 KEV EXP | Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 al… | Patch first | 8.8 high | 60.3% | 2018-11-14 |
| CVE-2020-8655 KEV EXP | An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to… | Patch first | 7.8 high | 60.1% | 2020-02-07 |
| CVE-2024-21338 KEV EXP | Windows Kernel Elevation of Privilege Vulnerability | Patch first | 7.8 high | 59.8% | 2024-02-13 |
| CVE-2017-0101 KEV EXP | The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Ser… | Patch first | 7.8 high | 57.5% | 2017-03-17 |
| CVE-2015-1701 KEV EXP | Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a… | Patch first | 7.8 high | 55.9% | 2015-04-21 |
| CVE-2026-2441 KEV EXP | Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML… | Patch first | 8.8 high | 55.1% | 2026-02-13 |
| CVE-2016-0984 KEV EXP | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 o… | Patch first | 8.8 high | 54.5% | 2016-02-10 |
| CVE-2019-0541 KEV EXP | A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vu… | Patch first | 8.8 high | 53.2% | 2019-01-08 |
| CVE-2015-2419 KEV EXP | JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption)… | Patch first | 8.8 high | 53.1% | 2015-07-14 |
| CVE-2019-0808 KEV EXP | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation… | Patch first | 7.8 high | 53% | 2019-04-09 |
| CVE-2019-13272 KEV EXP | In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptra… | Patch first | 7.8 high | 52.2% | 2019-07-17 |
| CVE-2019-13720 KEV EXP | Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML… | Patch first | 8.8 high | 49.1% | 2019-11-25 |
| CVE-2018-5430 KEV EXP | The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for… | Patch first | 8.8 high | 49% | 2018-04-17 |
| CVE-2014-4404 KEV EXP | Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged conte… | Patch first | 7.8 high | 48.9% | 2014-09-18 |
| CVE-2019-15752 KEV EXP | Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in… | Patch first | 7.8 high | 48.6% | 2019-08-28 |
| CVE-2013-2094 KEV EXP | The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users… | Patch first | 8.4 high | 47.7% | 2013-05-14 |
| CVE-2016-3976 KEV EXP | Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslas… | Patch first | 7.5 high | 47.3% | 2016-04-07 |
| CVE-2019-17026 KEV EXP | Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in t… | Patch first | 8.8 high | 46.3% | 2020-03-02 |
| CVE-2019-0803 KEV EXP | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation… | Patch first | 7.8 high | 45% | 2019-04-09 |
| CVE-2016-3235 KEV EXP | Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which al… | Patch first | 7.8 high | 43.3% | 2016-06-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt