CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,528 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,458 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-3298 KEV | Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 al… | Patch first | 6.5 medium | 33.3% | 2016-10-14 |
| CVE-2021-30633 KEV | Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentia… | Patch first | 9.6 critical | 33.2% | 2021-10-08 |
| CVE-2020-8195 KEV | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SD… | Patch first | 6.5 medium | 33% | 2020-07-10 |
| CVE-2020-35730 KEV | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mai… | Patch first | 6.1 medium | 32.7% | 2020-12-28 |
| CVE-2025-20393 KEV | A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could a… | Patch first | 10.0 critical | 32.4% | 2025-12-17 |
| CVE-2024-57968 KEV | Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during we… | Patch first | 9.9 critical | 32.3% | 2025-02-03 |
| CVE-2022-4135 KEV | Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially… | Patch first | 9.6 critical | 31.9% | 2022-11-25 |
| CVE-2026-20133 KEV | A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system.… | Patch first | 6.5 medium | 31.8% | 2026-02-25 |
| CVE-2026-0300 KEV | A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an una… | Patch first | 9.8 critical | 31.7% | 2026-05-06 |
| CVE-2022-24682 KEV | An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starti… | Patch first | 6.1 medium | 30.9% | 2022-02-09 |
| CVE-2021-27852 KEV | Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary c… | Patch first | 9.8 critical | 30.3% | 2021-05-27 |
| CVE-2021-20028 KEV | Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specificall… | Patch first | 9.8 critical | 30.1% | 2021-08-04 |
| CVE-2019-3568 KEV | A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target pho… | Patch first | 9.8 critical | 30.1% | 2019-05-14 |
| CVE-2025-32756 KEV | A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCa… | Patch first | 9.8 critical | 29.8% | 2025-05-13 |
| CVE-2018-6882 KEV | Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 an… | Patch first | 6.1 medium | 29.8% | 2018-03-27 |
| CVE-2025-68686 KEV | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7… | Patch first | 5.9 medium | 29.6% | 2026-02-10 |
| CVE-2026-20963 KEV | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | Patch first | 9.8 critical | 29.6% | 2026-01-13 |
| CVE-2018-20753 KEV | Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads… | Patch first | 9.8 critical | 29.3% | 2019-02-05 |
| CVE-2014-3931 KEV | fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption. | Patch first | 9.8 critical | 29% | 2017-03-31 |
| CVE-2023-33010 KEV | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmwar… | Patch first | 9.8 critical | 28.8% | 2023-05-24 |
| CVE-2018-19953 KEV | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the f… | Patch first | 6.1 medium | 28.8% | 2020-10-28 |
| CVE-2018-19949 KEV | If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the fol… | Patch first | 9.8 critical | 28.4% | 2020-10-28 |
| CVE-2024-11120 KEV | Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject an… | Patch first | 9.8 critical | 28.4% | 2024-11-15 |
| CVE-2020-3153 KEV | A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy… | Patch first | 6.5 medium | 28.3% | 2020-02-19 |
| CVE-2026-76461 KEV | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execu… | Patch first | 9.8 critical | 28.3% | 2026-09-14 |
| CVE-2026-20262 KEV | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a fil… | Patch first | 6.5 medium | 28.2% | 2026-06-15 |
| CVE-2023-33009 KEV | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware… | Patch first | 9.8 critical | 28.1% | 2023-05-24 |
| CVE-2020-5135 KEV | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending… | Patch first | 9.8 critical | 26.9% | 2020-10-12 |
| CVE-2024-37085 KEV | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access… | Patch first | 6.8 medium | 26.8% | 2024-06-25 |
| CVE-2025-14733 KEV | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code.… | Patch first | 9.8 critical | 26.5% | 2025-12-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt