CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,528 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
317,905 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-42292 KEV | Microsoft Excel Security Feature Bypass Vulnerability | Patch first | 7.8 high | 43% | 2021-11-10 |
| CVE-2020-0787 KEV | An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka… | Patch first | 7.8 high | 42.5% | 2020-03-12 |
| CVE-2024-41710 KEV | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136… | Patch first | 7.2 high | 41.6% | 2024-08-12 |
| CVE-2023-33538 KEV | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/… | Patch first | 8.8 high | 41.6% | 2023-06-07 |
| CVE-2024-38178 KEV | Scripting Engine Memory Corruption Vulnerability | Patch first | 7.5 high | 41.4% | 2024-08-13 |
| CVE-2023-4762 KEV | Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium s… | Patch first | 8.8 high | 41.4% | 2023-09-05 |
| CVE-2011-1823 KEV | The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local user… | Patch first | 7.8 high | 41.4% | 2011-06-09 |
| CVE-2021-22894 KEV | A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the… | Patch first | 8.8 high | 41.3% | 2021-05-27 |
| CVE-2022-21999 KEV | Windows Print Spooler Elevation of Privilege Vulnerability | Patch first | 7.8 high | 41% | 2022-02-09 |
| CVE-2023-21674 KEV | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Patch first | 8.8 high | 41% | 2023-01-10 |
| CVE-2023-2033 KEV | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… | Patch first | 8.8 high | 40.8% | 2023-04-14 |
| CVE-2017-5030 KEV | Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a… | Patch first | 8.8 high | 40.6% | 2017-04-24 |
| CVE-2015-2424 KEV | Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow… | Patch first | 8.8 high | 40.4% | 2015-07-14 |
| CVE-2015-0666 KEV | Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to r… | Patch first | 7.5 high | 40.4% | 2015-04-03 |
| CVE-2023-39780 KEV | On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter… | Patch first | 8.8 high | 40.2% | 2023-09-11 |
| CVE-2021-34448 KEV | Scripting Engine Memory Corruption Vulnerability | Patch first | 6.8 medium | 40.1% | 2021-07-16 |
| CVE-2014-0496 KEV | Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execut… | Patch first | 8.8 high | 40% | 2014-01-15 |
| CVE-2025-20352 KEV | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:… | Patch first | 7.7 high | 39.4% | 2025-09-24 |
| CVE-2021-1647 KEV | Microsoft Defender Remote Code Execution Vulnerability | Patch first | 7.8 high | 39.4% | 2021-01-12 |
| CVE-2021-26828 KEV | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via v… | Patch first | 8.8 high | 39.4% | 2021-06-11 |
| CVE-2020-1464 KEV | A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could by… | Patch first | 7.8 high | 38.9% | 2020-08-17 |
| CVE-2021-38003 KEV | Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a craft… | Patch first | 8.8 high | 38.6% | 2021-11-23 |
| CVE-2008-0655 KEV | Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors. | Patch first | 8.8 high | 37.9% | 2008-02-07 |
| CVE-2019-11001 KEV | On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to i… | Patch first | 7.2 high | 37.5% | 2019-04-08 |
| CVE-2020-17144 KEV | Microsoft Exchange Remote Code Execution Vulnerability | Patch first | 8.4 high | 36.5% | 2020-12-10 |
| CVE-2018-4990 KEV | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerabil… | Patch first | 8.8 high | 36.2% | 2018-07-09 |
| CVE-2021-39935 KEV | An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, a… | Patch first | 6.8 medium | 35.6% | 2021-12-13 |
| CVE-2018-17480 KEV | Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allo… | Patch first | 8.8 high | 35.6% | 2018-12-11 |
| CVE-2022-22960 KEV | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in supp… | Patch first | 7.8 high | 35.5% | 2022-04-13 |
| CVE-2020-13671 KEV | Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and s… | Patch first | 8.8 high | 35.4% | 2020-11-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt