CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,519 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
317,898 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-49897 KEV | An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vul… | Patch first | 8.8 high | 50.4% | 2023-12-06 |
| CVE-2013-7331 KEV | The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC s… | Patch first | 6.5 medium | 50.2% | 2014-02-26 |
| CVE-2021-22017 KEV | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acces… | Patch first | 5.3 medium | 49.2% | 2021-09-23 |
| CVE-2021-3493 KEV | The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files i… | Patch first | 8.8 high | 49.2% | 2021-04-17 |
| CVE-2023-37580 KEV | Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. | Patch first | 6.1 medium | 49.1% | 2023-07-31 |
| CVE-2023-5217 KEV | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exp… | Patch first | 8.8 high | 49% | 2023-09-28 |
| CVE-2015-1671 KEV | The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live… | Patch first | 7.8 high | 49% | 2015-05-13 |
| CVE-2023-28252 KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Patch first | 7.8 high | 49% | 2023-04-11 |
| CVE-2026-85046 KEV | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML… | Patch first | 8.8 high | 48.9% | 2026-09-03 |
| CVE-2025-68645 KEV | A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling o… | Patch first | 8.8 high | 48.9% | 2025-12-22 |
| CVE-2020-9715 KEV | Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-a… | Patch first | 7.8 high | 48.6% | 2020-08-19 |
| CVE-2020-16009 KEV | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a craf… | Patch first | 8.8 high | 48.3% | 2020-11-03 |
| CVE-2016-1646 KEV | The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider eleme… | Patch first | 8.8 high | 48.1% | 2016-03-29 |
| CVE-2006-2492 KEV | Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-ass… | Patch first | 8.8 high | 48.1% | 2006-05-20 |
| CVE-2021-26829 KEV | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. | Patch first | 5.4 medium | 48.1% | 2021-06-11 |
| CVE-2021-40407 KEV | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], base… | Patch first | 7.2 high | 47.6% | 2022-01-28 |
| CVE-2014-4123 KEV | Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privil… | Patch first | 8.8 high | 47.1% | 2014-10-15 |
| CVE-2022-39197 KEV | An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the C… | Patch first | 6.1 medium | 46.4% | 2022-09-22 |
| CVE-2019-1579 KEV | Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProt… | Patch first | 8.1 high | 46.2% | 2019-07-19 |
| CVE-2024-43573 KEV | Windows MSHTML Platform Spoofing Vulnerability | Patch first | 6.5 medium | 46.1% | 2024-10-08 |
| CVE-2017-16651 KEV | Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, in… | Patch first | 7.8 high | 45.7% | 2017-11-09 |
| CVE-2017-6737 KEV | A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely ex… | Patch first | 8.8 high | 45.2% | 2017-07-17 |
| CVE-2024-29988 KEV | SmartScreen Prompt Security Feature Bypass Vulnerability | Patch first | 8.8 high | 44.9% | 2024-04-09 |
| CVE-2015-2425 KEV | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch first | 8.8 high | 44.7% | 2015-07-14 |
| CVE-2013-3900 KEV | Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and… | Patch first | 5.5 medium | 44.6% | 2013-12-11 |
| CVE-2024-9379 KEV | SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrar… | Patch first | 6.5 medium | 43.8% | 2024-10-08 |
| CVE-2014-100005 KEV | Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to h… | Patch first | 8.0 high | 43.5% | 2015-01-13 |
| CVE-2023-36874 KEV | Windows Error Reporting Service Elevation of Privilege Vulnerability | Patch first | 7.8 high | 43.4% | 2023-07-11 |
| CVE-2007-0671 KEV | Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attacke… | Patch first | 8.8 high | 43.2% | 2007-02-03 |
| CVE-2009-0238 KEV | Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, a… | Patch first | 8.8 high | 43.2% | 2009-02-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt