CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,514 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
317,898 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-8651 KEV | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Ado… | Patch first | 8.8 high | 67.7% | 2015-12-28 |
| CVE-2009-0556 KEV | Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbi… | Patch first | 8.8 high | 67.3% | 2009-04-03 |
| CVE-2021-36934 KEV | An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Securi… | Patch first | 7.8 high | 67.3% | 2021-07-22 |
| CVE-2025-0411 KEV | 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected… | Patch first | 7.0 high | 67.1% | 2025-01-25 |
| CVE-2024-43572 KEV | Microsoft Management Console Remote Code Execution Vulnerability | Patch first | 7.8 high | 66.7% | 2024-10-08 |
| CVE-2013-0631 KEV | Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2… | Patch first | 7.5 high | 66.4% | 2013-01-09 |
| CVE-2021-36942 KEV | Windows LSA Spoofing Vulnerability | Patch first | 7.5 high | 66% | 2021-08-12 |
| CVE-2020-1020 KEV | A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted m… | Patch first | 8.8 high | 65% | 2020-04-15 |
| CVE-2021-27877 KEV | An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This auth… | Patch first | 8.2 high | 64.9% | 2021-03-01 |
| CVE-2014-1812 KEV | The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows… | Patch first | 8.8 high | 64.9% | 2014-05-14 |
| CVE-2021-30551 KEV | Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Patch first | 8.8 high | 64.7% | 2021-06-15 |
| CVE-2025-31125 KEV | Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicit… | Patch first | 5.3 medium | 64.7% | 2025-03-31 |
| CVE-2024-57728 KEV | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted z… | Patch first | 7.2 high | 64.7% | 2025-01-15 |
| CVE-2016-7256 KEV | atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2… | Patch first | 8.8 high | 64.6% | 2016-11-10 |
| CVE-2023-29552 KEV | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker… | Patch first | 7.5 high | 64% | 2023-04-25 |
| CVE-2023-43770 KEV | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/li… | Patch first | 6.1 medium | 63.7% | 2023-09-22 |
| CVE-2023-35081 KEV | A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated adminis… | Patch first | 7.2 high | 63.6% | 2023-08-03 |
| CVE-2021-30632 KEV | Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p… | Patch first | 8.8 high | 63.2% | 2021-10-08 |
| CVE-2025-47813 KEV | loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. | Patch first | 4.3 medium | 63% | 2025-07-10 |
| CVE-2009-0563 KEV | Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File F… | Patch first | 7.8 high | 62.8% | 2009-06-10 |
| CVE-2025-62593 KEV | Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerabil… | Patch first | 8.8 high | 62.5% | 2025-11-26 |
| CVE-2010-1428 KEV | The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 b… | Patch first | 7.5 high | 62.1% | 2010-04-28 |
| CVE-2018-8373 KEV | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engin… | Patch first | 7.5 high | 61.9% | 2018-08-15 |
| CVE-2023-21608 KEV | Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free v… | Patch first | 7.8 high | 61.5% | 2023-01-18 |
| CVE-2025-58360 KEV | GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML… | Patch first | 8.2 high | 60.5% | 2025-11-25 |
| CVE-2014-4148 KEV | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind… | Patch first | 8.8 high | 59.9% | 2014-10-15 |
| CVE-2024-9380 KEV | An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin pr… | Patch first | 7.2 high | 59.7% | 2024-10-08 |
| CVE-2017-11774 KEV | Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office… | Patch first | 7.8 high | 59.6% | 2017-10-13 |
| CVE-2021-33742 KEV | Windows MSHTML Platform Remote Code Execution Vulnerability | Patch first | 7.5 high | 59.4% | 2021-06-08 |
| CVE-2023-21529 KEV | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch first | 8.8 high | 59.3% | 2023-02-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt