CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,529 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,458 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-7836 KEV | SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the manag… | Patch first | 9.8 critical | 19.2% | 2017-06-09 |
| CVE-2026-72898 KEV | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access t… | Patch first | 10.0 critical | 19% | 2026-08-10 |
| CVE-2026-9586 KEV | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning… | Patch first | 9.8 critical | 19% | 2026-07-17 |
| CVE-2015-5123 KEV | Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windo… | Patch first | 9.8 critical | 18.8% | 2015-07-14 |
| CVE-2014-2120 KEV | Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to injec… | Patch first | 6.1 medium | 18.8% | 2014-03-19 |
| CVE-2025-31200 KEV | A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS… | Patch first | 9.8 critical | 18.8% | 2025-04-16 |
| CVE-2020-11899 KEV | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. | Patch first | 5.4 medium | 18.6% | 2020-06-17 |
| CVE-2019-5591 KEV | A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impers… | Patch first | 6.5 medium | 18.4% | 2020-08-14 |
| CVE-2024-40766 KEV | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource… | Patch first | 9.8 critical | 18.4% | 2024-08-23 |
| CVE-2018-0147 KEV | A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated,… | Patch first | 9.8 critical | 18.2% | 2018-03-08 |
| CVE-2017-0022 KEV | Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1… | Patch first | 6.5 medium | 18.1% | 2017-03-17 |
| CVE-2023-42916 KEV | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 1… | Patch first | 6.5 medium | 17.8% | 2023-11-30 |
| CVE-2010-5326 KEV | The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote atta… | Patch first | 10.0 critical | 17.8% | 2016-05-13 |
| CVE-2024-11182 KEV | An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img… | Patch first | 6.1 medium | 17.7% | 2024-11-15 |
| CVE-2022-27926 KEV | A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthe… | Patch first | 6.1 medium | 17.6% | 2022-04-21 |
| CVE-2026-55040 KEV | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. | Patch first | 9.1 critical | 17.5% | 2026-07-14 |
| CVE-2020-4006 KEV | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. | Patch first | 9.1 critical | 17.3% | 2020-11-23 |
| CVE-2023-26359 KEV | Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerabili… | Patch first | 9.8 critical | 17% | 2023-03-23 |
| CVE-2021-30533 KEV | Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via… | Patch first | 6.5 medium | 16.6% | 2021-06-07 |
| CVE-2020-27950 KEV | A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020… | Patch first | 5.5 medium | 16.5% | 2020-12-08 |
| CVE-2023-6345 KEV | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially pe… | Patch first | 9.6 critical | 16.5% | 2023-11-29 |
| CVE-2026-58644 KEV | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | Patch first | 9.8 critical | 15.9% | 2026-07-14 |
| CVE-2024-20481 KEV | A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)… | Patch first | 5.8 medium | 15.8% | 2024-10-23 |
| CVE-2023-50224 KEV | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to di… | Patch first | 6.5 medium | 15.6% | 2024-05-03 |
| CVE-2024-4947 KEV | Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML p… | Patch first | 9.6 critical | 15.2% | 2024-05-15 |
| CVE-2026-34908 KEV | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized cha… | Patch first | 10.0 critical | 15.2% | 2026-05-22 |
| CVE-2022-20708 KEV | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch first | 10.0 critical | 14.9% | 2022-02-10 |
| CVE-2026-56291 KEV | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to… | Patch first | 9.8 critical | 14.9% | 2026-07-09 |
| CVE-2020-10181 KEV | goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) o… | Patch first | 9.8 critical | 14.7% | 2020-03-11 |
| CVE-2019-7193 KEV | This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend… | Patch first | 9.8 critical | 14.4% | 2019-12-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt