CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,482 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
201 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-4723 KEV | The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors… | Patch first | 5.7 medium | 3.1% | 2011-12-20 |
| CVE-2023-36584 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 3.1% | 2023-10-10 |
| CVE-2021-31199 KEV | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | Patch first | 5.2 medium | 3% | 2021-06-08 |
| CVE-2023-38606 KEV | This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPad… | Patch first | 5.5 medium | 2.9% | 2023-07-27 |
| CVE-2021-25337 KEV | Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write… | Patch first | 4.4 medium | 2.8% | 2021-03-04 |
| CVE-2025-40602 KEV | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). | Patch first | 6.6 medium | 2.8% | 2025-12-18 |
| CVE-2020-0878 KEV | <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in… | Patch first | 4.2 medium | 2.7% | 2020-09-11 |
| CVE-2021-31201 KEV | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | Patch first | 5.2 medium | 2.6% | 2021-06-08 |
| CVE-2023-21492 KEV | Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. | Patch first | 4.4 medium | 2.6% | 2023-05-04 |
| CVE-2022-41049 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 2.5% | 2022-11-09 |
| CVE-2023-20109 KEV | A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authentica… | Patch first | 6.6 medium | 2.3% | 2023-09-27 |
| CVE-2020-9819 KEV | A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, wa… | Patch first | 4.3 medium | 2.2% | 2020-06-09 |
| CVE-2017-12232 KEV | A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through… | Patch first | 6.5 medium | 2.2% | 2017-09-29 |
| CVE-2017-6663 KEV | A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker… | Patch first | 6.5 medium | 2.1% | 2017-08-07 |
| CVE-2017-12238 KEV | A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an u… | Patch first | 6.5 medium | 2% | 2017-09-29 |
| CVE-2025-0111 KEV | An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the manage… | Patch first | 6.5 medium | 2% | 2025-02-12 |
| CVE-2025-24991 KEV | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | Patch first | 5.5 medium | 2% | 2025-03-11 |
| CVE-2025-24984 KEV | Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. | Patch first | 4.6 medium | 2% | 2025-03-11 |
| CVE-2025-59689 KEV | Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.3… | Patch first | 6.1 medium | 1.9% | 2025-09-19 |
| CVE-2022-41091 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 1.8% | 2022-11-09 |
| CVE-2025-21590 KEV | An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to… | Patch first | 4.4 medium | 1.7% | 2025-03-12 |
| CVE-2025-48700 KEV | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Class… | Patch first | 6.1 medium | 1.7% | 2025-06-23 |
| CVE-2024-39891 KEV | In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain p… | Patch first | 5.3 medium | 1.7% | 2024-07-02 |
| CVE-2025-35939 KEV | Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an… | Patch first | 5.3 medium | 1.3% | 2025-05-07 |
| CVE-2026-45498 KEV | Microsoft Defender Denial of Service Vulnerability | Patch first | 4.0 medium | 1.3% | 2026-05-20 |
| CVE-2025-43200 KEV | This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPa… | Patch first | 4.2 medium | 1.2% | 2025-06-16 |
| CVE-2022-22674 KEV | An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixe… | Patch first | 5.5 medium | 1.1% | 2022-05-26 |
| CVE-2023-36851 KEV | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attac… | Patch first | 5.3 medium | 1.1% | 2023-09-27 |
| CVE-2021-25369 KEV | An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. | Patch first | 6.2 medium | 1.1% | 2021-03-26 |
| CVE-2023-4211 KEV | A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. | Patch first | 5.5 medium | 1.1% | 2023-10-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt