CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,482 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
1,726 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-0249 KEV EXP | Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; W… | Patch first | 8.8 high | 91.9% | 2010-01-15 |
| CVE-2020-8657 KEV EXP | An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API ver… | Patch first | 9.8 critical | 91.9% | 2020-02-06 |
| CVE-2025-64446 KEV EXP | A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb… | Patch first | 9.8 critical | 91.8% | 2025-11-14 |
| CVE-2024-5910 KEV EXP | Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with ne… | Patch first | 9.8 critical | 91.8% | 2024-07-10 |
| CVE-2018-11138 KEV EXP | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be ab… | Patch first | 9.8 critical | 91.8% | 2018-05-31 |
| CVE-2010-2568 KEV EXP | Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote atta… | Patch first | 7.8 high | 91.3% | 2010-07-22 |
| CVE-2012-5076 KEV EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect c… | Patch first | 9.8 critical | 91.3% | 2012-10-16 |
| CVE-2012-0754 KEV EXP | Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x;… | Patch first | 8.1 high | 91.2% | 2012-02-16 |
| CVE-2017-3066 KEV EXP | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulne… | Patch first | 9.8 critical | 90.6% | 2017-04-27 |
| CVE-2020-3952 KEV EXP | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not… | Patch first | 9.8 critical | 90.4% | 2020-04-10 |
| CVE-2013-0431 KEV EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted r… | Patch first | 5.3 medium | 90.2% | 2013-01-31 |
| CVE-2009-3960 KEV EXP | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex… | Patch first | 6.5 medium | 90.1% | 2010-02-15 |
| CVE-2017-8464 KEV EXP | Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,… | Patch first | 8.8 high | 89.9% | 2017-06-15 |
| CVE-2017-8570 KEV EXP | Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Exec… | Patch first | 7.8 high | 89.9% | 2017-07-11 |
| CVE-2017-0146 KEV EXP | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Wind… | Patch first | 8.8 high | 89.9% | 2017-03-17 |
| CVE-2017-0145 KEV EXP | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Wind… | Patch first | 8.8 high | 89.9% | 2017-03-17 |
| CVE-2018-15982 KEV EXP | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to ar… | Patch first | 7.8 high | 89.6% | 2019-01-18 |
| CVE-2018-4878 KEV EXP | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Prim… | Patch first | 7.8 high | 89.5% | 2018-02-06 |
| CVE-2010-3333 KEV EXP | Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 20… | Patch first | 7.8 high | 89.5% | 2010-11-10 |
| CVE-2020-0601 KEV EXP | A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could… | Patch first | 8.1 high | 89.4% | 2020-01-14 |
| CVE-2017-5521 KEV EXP | An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices… | Patch first | 8.1 high | 89.2% | 2017-01-17 |
| CVE-2017-8759 KEV EXP | Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or appl… | Patch first | 7.8 high | 88.7% | 2017-09-13 |
| CVE-2014-3120 KEV EXP | The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions a… | Patch first | 8.1 high | 88.6% | 2014-07-28 |
| CVE-2011-2462 KEV EXP | Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.… | Patch first | 9.8 critical | 88.5% | 2011-12-07 |
| CVE-2021-43798 KEV EXP | Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vuln… | Patch first | 7.5 high | 88.5% | 2021-12-07 |
| CVE-2018-8174 KEV EXP | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code E… | Patch first | 7.5 high | 88.3% | 2018-05-09 |
| CVE-2010-0188 KEV EXP | Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application… | Patch first | 7.8 high | 88.2% | 2010-02-22 |
| CVE-2016-6415 KEV EXP | The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and… | Patch first | 7.5 high | 87.7% | 2016-09-19 |
| CVE-2016-6366 KEV EXP | Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Fir… | Patch first | 8.8 high | 87.6% | 2016-08-18 |
| CVE-2013-3893 KEV EXP | Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers t… | Patch first | 8.8 high | 87.5% | 2013-09-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt