CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,483 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
902 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2019-7286 KEV EXP | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. A… | Patch first | 7.8 high | 15.9% | 2019-12-18 |
| CVE-2020-3837 KEV EXP | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tv… | Patch first | 7.8 high | 14.7% | 2020-02-27 |
| CVE-2018-14634 KEV EXP | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise pr… | Patch first | 7.8 high | 14.7% | 2018-09-25 |
| CVE-2010-3904 KEV EXP | The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 doe… | Patch first | 7.8 high | 14.5% | 2010-12-06 |
| CVE-2016-0165 KEV EXP | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2… | Patch first | 7.8 high | 13.7% | 2016-04-12 |
| CVE-2019-3010 KEV EXP | Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploita… | Patch first | 8.8 high | 13.4% | 2019-10-16 |
| CVE-2019-1253 KEV EXP | An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an… | Patch first | 7.8 high | 11.6% | 2019-09-11 |
| CVE-2017-1000253 KEV EXP | Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committe… | Patch first | 7.8 high | 10.7% | 2017-10-05 |
| CVE-2017-0263 KEV EXP | The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,… | Patch first | 7.8 high | 10% | 2017-05-12 |
| CVE-2025-21333 KEV EXP | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Patch first | 7.8 high | 10% | 2025-01-14 |
| CVE-2015-1130 KEV EXP | The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via uns… | Patch first | 7.8 high | 9.9% | 2015-04-10 |
| CVE-2019-1132 KEV EXP | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation… | Patch first | 7.8 high | 9.8% | 2019-07-15 |
| CVE-2025-2783 KEV EXP | Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perfor… | Patch first | 8.3 high | 9.2% | 2025-03-26 |
| CVE-2015-2291 KEV EXP | (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a den… | Patch first | 7.8 high | 9% | 2017-08-09 |
| CVE-2010-4398 KEV EXP | Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows… | Patch first | 7.8 high | 8.7% | 2010-12-06 |
| CVE-2020-0683 KEV EXP | An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of… | Patch first | 7.8 high | 7.6% | 2020-02-11 |
| CVE-2020-3950 KEV EXP | VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.… | Patch first | 7.8 high | 7.3% | 2020-03-17 |
| CVE-2004-0210 KEV EXP | The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifyin… | Patch first | 7.8 high | 7.2% | 2004-08-06 |
| CVE-2008-3431 KEV EXP | The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does… | Patch first | 8.8 high | 6.9% | 2008-08-05 |
| CVE-2025-62215 KEV EXP | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate… | Patch first | 7.0 high | 6% | 2025-11-11 |
| CVE-2019-0863 KEV EXP | An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privi… | Patch first | 7.8 high | 5.2% | 2019-05-16 |
| CVE-2015-5287 KEV EXP | The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via… | Patch first | 7.8 high | 5% | 2015-12-07 |
| CVE-2002-0367 KEV EXP | smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local… | Patch first | 7.8 high | 4.9% | 2002-06-25 |
| CVE-2019-0543 KEV EXP | An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege… | Patch first | 7.8 high | 4.7% | 2019-01-08 |
| CVE-2016-3643 KEV EXP | SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by… | Patch first | 7.8 high | 3.7% | 2016-06-17 |
| CVE-2023-32315 KEV | Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be… | Patch first | 8.6 high | 100% | 2023-05-26 |
| CVE-2024-21893 KEV | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti… | Patch first | 8.2 high | 100% | 2024-01-31 |
| CVE-2024-3273 KEV | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to… | Patch first | 7.3 high | 100% | 2024-04-04 |
| CVE-2025-49704 KEV | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | Patch first | 8.8 high | 100% | 2025-07-08 |
| CVE-2024-27199 KEV | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible | Patch first | 7.3 high | 100% | 2024-03-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt