CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
317,898 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-21882 KEV | Win32k Elevation of Privilege Vulnerability | Patch first | 7.0 high | 59.2% | 2022-01-11 |
| CVE-2010-2572 KEV | Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document,… | Patch first | 7.8 high | 58.6% | 2010-11-10 |
| CVE-2019-1068 KEV | A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL… | Patch first | 8.8 high | 57.9% | 2019-07-15 |
| CVE-2016-7262 KEV | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-as… | Patch first | 7.8 high | 57.7% | 2016-12-20 |
| CVE-2023-6549 KEV | Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Servic… | Patch first | 8.2 high | 57.6% | 2024-01-17 |
| CVE-2016-7193 KEV | Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack… | Patch first | 7.8 high | 57.6% | 2016-10-14 |
| CVE-2025-25181 KEV | A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands v… | Patch first | 5.8 medium | 57.3% | 2025-02-03 |
| CVE-2021-25297 KEV | Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/s… | Patch first | 8.8 high | 56.7% | 2021-02-15 |
| CVE-2025-58034 KEV | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWe… | Patch first | 7.2 high | 55.6% | 2025-11-18 |
| CVE-2006-1547 KEV | ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multi… | Patch first | 7.5 high | 54.6% | 2006-03-30 |
| CVE-2014-4077 KEV | Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IM… | Patch first | 7.8 high | 54.6% | 2014-11-11 |
| CVE-2024-43461 KEV | Windows MSHTML Platform Spoofing Vulnerability | Patch first | 8.8 high | 54.5% | 2024-09-10 |
| CVE-2020-1054 KEV | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker… | Patch first | 7.0 high | 54.2% | 2020-05-21 |
| CVE-2023-20118 KEV | A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allo… | Patch first | 6.5 medium | 54.1% | 2023-04-13 |
| CVE-2021-31196 KEV | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch first | 7.2 high | 54.1% | 2021-07-14 |
| CVE-2020-25079 KEV | An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated comman… | Patch first | 8.8 high | 54% | 2020-09-02 |
| CVE-2022-21971 KEV | Windows Runtime Remote Code Execution Vulnerability | Patch first | 7.8 high | 53.9% | 2022-02-09 |
| CVE-2014-0130 KEV | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18,… | Patch first | 7.5 high | 53.7% | 2014-05-07 |
| CVE-2023-41064 KEV | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS… | Patch first | 7.8 high | 53.4% | 2023-09-07 |
| CVE-2021-22175 KEV | When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting… | Patch first | 6.8 medium | 53.4% | 2021-06-11 |
| CVE-2015-1642 KEV | Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memo… | Patch first | 7.8 high | 53.1% | 2015-08-15 |
| CVE-2012-2539 KEV | Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote… | Patch first | 7.8 high | 53% | 2012-12-12 |
| CVE-2009-0557 KEV | Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP… | Patch first | 7.8 high | 53% | 2009-06-10 |
| CVE-2019-1367 KEV | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin… | Patch first | 7.5 high | 52.4% | 2019-09-23 |
| CVE-2021-28550 KEV | Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use… | Patch first | 8.8 high | 52% | 2021-09-02 |
| CVE-2023-32434 KEV | An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15… | Patch first | 7.8 high | 51.5% | 2023-06-23 |
| CVE-2021-20023 KEV | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote h… | Patch first | 4.9 medium | 51.4% | 2021-04-20 |
| CVE-2009-1537 KEV | Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4,… | Patch first | 8.8 high | 51.2% | 2009-05-29 |
| CVE-2015-2502 KEV | Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… | Patch first | 8.8 high | 51% | 2015-08-19 |
| CVE-2024-38094 KEV | Microsoft SharePoint Remote Code Execution Vulnerability | Patch first | 7.2 high | 50.9% | 2024-07-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt