CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,424 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-26
168,968 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-49706 KEV | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | Patch first | 6.5 medium | 99.1% | 2025-07-08 |
| CVE-2023-36846 KEV | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attac… | Patch first | 5.3 medium | 93.5% | 2023-08-17 |
| CVE-2023-41763 KEV | Skype for Business Elevation of Privilege Vulnerability | Patch first | 5.3 medium | 90.4% | 2023-10-10 |
| CVE-2023-36844 KEV | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacke… | Patch first | 5.3 medium | 90% | 2023-08-17 |
| CVE-2020-8193 KEV | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWA… | Patch first | 6.5 medium | 88.4% | 2020-07-10 |
| CVE-2021-21973 KEV | The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin.… | Patch first | 5.3 medium | 87.6% | 2021-02-24 |
| CVE-2025-20362 KEV | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software… | Patch first | 6.5 medium | 87.1% | 2025-09-25 |
| CVE-2020-3580 KEV | Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) So… | Patch first | 6.1 medium | 85.6% | 2020-10-21 |
| CVE-2024-43451 KEV | NTLM Hash Disclosure Spoofing Vulnerability | Patch first | 6.5 medium | 84.1% | 2024-11-12 |
| CVE-2023-36847 KEV | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attack… | Patch first | 5.3 medium | 83.5% | 2023-08-17 |
| CVE-2024-0769 KEV | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unk… | Patch first | 5.3 medium | 82.7% | 2024-01-21 |
| CVE-2021-31955 KEV | Windows Kernel Information Disclosure Vulnerability | Patch first | 5.5 medium | 81.1% | 2021-06-08 |
| CVE-2018-18809 KEV | The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperRep… | Patch first | 6.5 medium | 79.1% | 2019-03-07 |
| CVE-2023-24880 KEV | Windows SmartScreen Security Feature Bypass Vulnerability | Patch first | 4.4 medium | 78% | 2023-03-14 |
| CVE-2020-13965 KEV | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is amo… | Patch first | 6.1 medium | 76.6% | 2020-06-09 |
| CVE-2022-44698 KEV | Windows SmartScreen Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 76.3% | 2022-12-13 |
| CVE-2023-5631 KEV | Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because o… | Patch first | 6.1 medium | 75.9% | 2023-10-18 |
| CVE-2022-28810 KEV | Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTE… | Patch first | 6.8 medium | 71% | 2022-04-18 |
| CVE-2020-4430 KEV | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker co… | Patch first | 4.3 medium | 68.5% | 2020-05-07 |
| CVE-2021-30657 KEV | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious… | Patch first | 5.5 medium | 68.5% | 2021-09-08 |
| CVE-2025-31125 KEV | Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicit… | Patch first | 5.3 medium | 64.7% | 2025-03-31 |
| CVE-2023-43770 KEV | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/li… | Patch first | 6.1 medium | 63.7% | 2023-09-22 |
| CVE-2025-47813 KEV | loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. | Patch first | 4.3 medium | 63% | 2025-07-10 |
| CVE-2025-25181 KEV | A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands v… | Patch first | 5.8 medium | 57.3% | 2025-02-03 |
| CVE-2023-20118 KEV | A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allo… | Patch first | 6.5 medium | 54.1% | 2023-04-13 |
| CVE-2021-22175 KEV | When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting… | Patch first | 6.8 medium | 53.4% | 2021-06-11 |
| CVE-2021-20023 KEV | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote h… | Patch first | 4.9 medium | 51.4% | 2021-04-20 |
| CVE-2013-7331 KEV | The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC s… | Patch first | 6.5 medium | 50.2% | 2014-02-26 |
| CVE-2021-22017 KEV | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acces… | Patch first | 5.3 medium | 49.2% | 2021-09-23 |
| CVE-2023-37580 KEV | Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. | Patch first | 6.1 medium | 49.1% | 2023-07-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt