CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,483 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
398,483 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-3765 KEV EXP | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10… | Patch first | 9.8 critical | 83.2% | 2010-10-28 |
| CVE-2015-1187 KEV EXP | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp. | Patch first | 9.8 critical | 82.9% | 2017-09-21 |
| CVE-2016-7200 KEV EXP | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corrup… | Patch first | 8.8 high | 82.8% | 2016-11-10 |
| CVE-2025-33073 KEV EXP | Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | Patch first | 8.8 high | 82.7% | 2025-06-10 |
| CVE-2010-1297 KEV EXP | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x b… | Patch first | 7.8 high | 82.2% | 2010-06-08 |
| CVE-2010-0806 KEV EXP | Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to… | Patch first | 8.8 high | 82.2% | 2010-03-10 |
| CVE-2018-6789 KEV EXP | An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may ha… | Patch first | 9.8 critical | 82.1% | 2018-02-08 |
| CVE-2009-4324 KEV EXP | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Win… | Patch first | 7.8 high | 81.9% | 2009-12-15 |
| CVE-2018-13382 KEV EXP | An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1… | Patch first | 9.1 critical | 81.7% | 2019-06-04 |
| CVE-2014-4114 KEV EXP | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows R… | Patch first | 7.8 high | 81.6% | 2014-10-15 |
| CVE-2019-0752 KEV EXP | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin… | Patch first | 7.5 high | 81.6% | 2019-04-09 |
| CVE-2023-4911 KEV EXP | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue coul… | Patch first | 7.8 high | 81.4% | 2023-10-03 |
| CVE-2010-2883 KEV EXP | Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote at… | Patch first | 7.3 high | 81.4% | 2010-09-09 |
| CVE-2019-9621 KEV EXP | Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SS… | Patch first | 7.5 high | 81% | 2019-04-30 |
| CVE-2016-7255 KEV EXP | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… | Patch first | 7.8 high | 81% | 2016-11-10 |
| CVE-2017-0037 KEV EXP | Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSp… | Patch first | 8.1 high | 80.4% | 2017-02-26 |
| CVE-2012-4969 KEV EXP | Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execu… | Patch first | 8.1 high | 80.3% | 2012-09-18 |
| CVE-2020-14871 KEV EXP | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 1… | Patch first | 10.0 critical | 80.2% | 2020-10-21 |
| CVE-2016-7201 KEV EXP | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corrup… | Patch first | 8.8 high | 80% | 2016-11-10 |
| CVE-2013-4810 KEV EXP | HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attack… | Patch first | 9.8 critical | 79.5% | 2013-09-16 |
| CVE-2010-0738 KEV EXP | The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 bef… | Patch first | 5.3 medium | 79.4% | 2010-04-28 |
| CVE-2021-21551 KEV EXP | Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or inf… | Patch first | 8.8 high | 79.2% | 2021-05-04 |
| CVE-2013-3346 KEV EXP | Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of… | Patch first | 9.8 critical | 78.9% | 2013-08-30 |
| CVE-2013-0074 KEV EXP | Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows re… | Patch first | 7.8 high | 78.9% | 2013-03-13 |
| CVE-2012-4792 KEV EXP | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that… | Patch first | 8.8 high | 78.8% | 2012-12-30 |
| CVE-2020-6418 KEV EXP | Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Patch first | 8.8 high | 78.8% | 2020-02-27 |
| CVE-2021-22555 KEV EXP | A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or… | Patch first | 8.3 high | 78.7% | 2021-07-07 |
| CVE-2020-8816 KEV EXP | Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease. | Patch first | 7.2 high | 78.2% | 2020-05-29 |
| CVE-2013-1347 KEV EXP | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an obje… | Patch first | 8.8 high | 77.7% | 2013-05-05 |
| CVE-2017-11357 KEV EXP | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perf… | Patch first | 9.8 critical | 77.7% | 2017-08-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt