CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,503 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
317,898 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-32648 KEV | octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account… | Patch first | 8.2 high | 90.4% | 2021-08-26 |
| CVE-2023-41763 KEV | Skype for Business Elevation of Privilege Vulnerability | Patch first | 5.3 medium | 90.4% | 2023-10-10 |
| CVE-2021-20123 KEV | A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. A… | Patch first | 7.5 high | 90.2% | 2021-10-13 |
| CVE-2023-36844 KEV | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacke… | Patch first | 5.3 medium | 90% | 2023-08-17 |
| CVE-2023-20273 KEV | A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of… | Patch first | 7.2 high | 89.6% | 2023-10-25 |
| CVE-2024-8190 KEV | An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to o… | Patch first | 7.2 high | 88.5% | 2024-09-10 |
| CVE-2020-8193 KEV | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWA… | Patch first | 6.5 medium | 88.4% | 2020-07-10 |
| CVE-2026-20230 KEV | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM S… | Patch first | 8.6 high | 88.2% | 2026-06-03 |
| CVE-2023-36025 KEV | Windows SmartScreen Security Feature Bypass Vulnerability | Patch first | 8.8 high | 88.1% | 2023-11-14 |
| CVE-2025-29635 KEV | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices b… | Patch first | 7.2 high | 87.9% | 2025-03-25 |
| CVE-2012-0151 KEV | The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008… | Patch first | 7.8 high | 87.7% | 2012-04-10 |
| CVE-2026-1603 KEV | An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credentia… | Patch first | 8.6 high | 87.6% | 2026-02-10 |
| CVE-2021-21973 KEV | The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin.… | Patch first | 5.3 medium | 87.6% | 2021-02-24 |
| CVE-2025-20362 KEV | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software… | Patch first | 6.5 medium | 87.1% | 2025-09-25 |
| CVE-2025-33053 KEV | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | Patch first | 8.8 high | 87% | 2025-06-10 |
| CVE-2021-40655 KEV | An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a pos… | Patch first | 7.5 high | 86.7% | 2021-09-24 |
| CVE-2025-4428 KEV | Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to… | Patch first | 7.2 high | 86.5% | 2025-05-13 |
| CVE-2021-21017 KEV | Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap… | Patch first | 8.8 high | 86.3% | 2021-02-11 |
| CVE-2015-2545 KEV | Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microso… | Patch first | 7.8 high | 85.9% | 2015-09-09 |
| CVE-2020-3580 KEV | Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) So… | Patch first | 6.1 medium | 85.6% | 2020-10-21 |
| CVE-2022-27924 KEV | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These… | Patch first | 7.5 high | 85.4% | 2022-04-21 |
| CVE-2023-24955 KEV | Microsoft SharePoint Server Remote Code Execution Vulnerability | Patch first | 7.2 high | 85.4% | 2023-05-09 |
| CVE-2021-1675 KEV | Windows Print Spooler Remote Code Execution Vulnerability | Patch first | 7.8 high | 85.3% | 2021-06-08 |
| CVE-2025-8110 KEV | Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. | Patch first | 8.8 high | 85.2% | 2025-12-10 |
| CVE-2023-41266 KEV | A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier… | Patch first | 8.2 high | 84.8% | 2023-08-29 |
| CVE-2025-64328 KEV | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore… | Patch first | 7.2 high | 84.6% | 2025-11-07 |
| CVE-2020-28949 KEV | Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to ov… | Patch first | 7.8 high | 84.6% | 2020-11-19 |
| CVE-2024-38112 KEV | Windows MSHTML Platform Spoofing Vulnerability | Patch first | 7.5 high | 84.2% | 2024-07-09 |
| CVE-2021-21224 KEV | Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pa… | Patch first | 8.8 high | 84.2% | 2021-04-26 |
| CVE-2024-43451 KEV | NTLM Hash Disclosure Spoofing Vulnerability | Patch first | 6.5 medium | 84.1% | 2024-11-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt