CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,528 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
317,905 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-20316 KEV | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log… | Patch first | 5.3 medium | 35.1% | 2026-07-29 |
| CVE-2015-1770 KEV | Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Unini… | Patch first | 8.8 high | 35% | 2015-06-10 |
| CVE-2021-37975 KEV | Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Patch first | 8.8 high | 34.9% | 2021-10-08 |
| CVE-2015-2387 KEV | ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7… | Patch first | 7.8 high | 34.9% | 2015-07-14 |
| CVE-2016-5198 KEV | V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisatio… | Patch first | 8.8 high | 34.2% | 2017-01-19 |
| CVE-2022-40799 KEV | Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device. | Patch first | 8.8 high | 33.7% | 2022-11-29 |
| CVE-2018-13383 KEV | A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1… | Patch first | 4.3 medium | 33.6% | 2019-05-29 |
| CVE-2015-0071 KEV | Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explore… | Patch first | 6.5 medium | 33.6% | 2015-02-11 |
| CVE-2025-9377 KEV | The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V… | Patch first | 7.2 high | 33.5% | 2025-08-29 |
| CVE-2016-3298 KEV | Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 al… | Patch first | 6.5 medium | 33.3% | 2016-10-14 |
| CVE-2025-21042 KEV | Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. | Patch first | 8.8 high | 33.2% | 2025-09-12 |
| CVE-2020-8195 KEV | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SD… | Patch first | 6.5 medium | 33% | 2020-07-10 |
| CVE-2020-35730 KEV | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mai… | Patch first | 6.1 medium | 32.7% | 2020-12-28 |
| CVE-2013-0641 KEV | Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary… | Patch first | 7.8 high | 32.3% | 2013-02-14 |
| CVE-2020-8218 KEV | A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution v… | Patch first | 7.2 high | 32.3% | 2020-07-30 |
| CVE-2023-3079 KEV | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… | Patch first | 8.8 high | 32.1% | 2023-06-05 |
| CVE-2017-5070 KEV | Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to ex… | Patch first | 8.8 high | 32.1% | 2017-10-27 |
| CVE-2026-20133 KEV | A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system.… | Patch first | 6.5 medium | 31.8% | 2026-02-25 |
| CVE-2025-0994 KEV | Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerabili… | Patch first | 8.8 high | 31.3% | 2025-02-06 |
| CVE-2016-4523 KEV | The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bou… | Patch first | 7.5 high | 31.2% | 2016-06-09 |
| CVE-2022-24682 KEV | An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starti… | Patch first | 6.1 medium | 30.9% | 2022-02-09 |
| CVE-2020-0968 KEV | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin… | Patch first | 7.5 high | 30.7% | 2020-04-15 |
| CVE-2019-13608 KEV | Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks. | Patch first | 7.5 high | 30% | 2019-08-29 |
| CVE-2018-6882 KEV | Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 an… | Patch first | 6.1 medium | 29.8% | 2018-03-27 |
| CVE-2017-0222 KEV | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vu… | Patch first | 8.8 high | 29.6% | 2017-05-12 |
| CVE-2018-8653 KEV | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engin… | Patch first | 7.5 high | 29.6% | 2018-12-20 |
| CVE-2025-68686 KEV | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7… | Patch first | 5.9 medium | 29.6% | 2026-02-10 |
| CVE-2023-2533 KEV | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an… | Patch first | 8.4 high | 29.2% | 2023-06-20 |
| CVE-2017-0149 KEV | Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft… | Patch first | 8.8 high | 29.2% | 2017-03-17 |
| CVE-2021-30807 KEV | A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watc… | Patch first | 7.8 high | 28.8% | 2021-10-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt