CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,553 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,466 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-28204 KEV | An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and… | Patch first | 6.5 medium | 14.3% | 2023-06-23 |
| CVE-2018-0151 KEV | A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attac… | Patch first | 9.8 critical | 14.2% | 2018-03-28 |
| CVE-2026-82329 KEV | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to… | Patch first | 9.8 critical | 14.1% | 2026-08-28 |
| CVE-2026-76460 KEV | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vu… | Patch first | 10.0 critical | 14% | 2026-09-16 |
| CVE-2025-31201 KEV | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visi… | Patch first | 9.8 critical | 14% | 2025-04-16 |
| CVE-2025-42999 KEV | SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialize… | Patch first | 9.1 critical | 13.9% | 2025-05-13 |
| CVE-2017-12240 KEV | The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote… | Patch first | 9.8 critical | 13.8% | 2017-09-29 |
| CVE-2024-12686 KEV | A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative… | Patch first | 6.6 medium | 13.7% | 2024-12-18 |
| CVE-2024-38213 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 6.5 medium | 13.6% | 2024-08-13 |
| CVE-2015-4902 KEV | Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deploymen… | Patch first | 5.3 medium | 13.6% | 2015-10-22 |
| CVE-2023-41991 KEV | A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypa… | Patch first | 5.5 medium | 13.4% | 2023-09-21 |
| CVE-2026-22769 KEV | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an… | Patch first | 10.0 critical | 13.3% | 2026-02-17 |
| CVE-2022-22948 KEV | The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative acc… | Patch first | 6.5 medium | 13.3% | 2022-03-29 |
| CVE-2026-86218 KEV | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. | Patch first | 9.8 critical | 12.9% | 2026-09-06 |
| CVE-2024-21410 KEV | Microsoft Exchange Server Elevation of Privilege Vulnerability | Patch first | 9.8 critical | 12.6% | 2024-02-13 |
| CVE-2020-8599 KEV | Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an ar… | Patch first | 9.8 critical | 11.9% | 2020-03-18 |
| CVE-2021-37973 KEV | Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially per… | Patch first | 9.6 critical | 11.7% | 2021-10-08 |
| CVE-2022-22587 KEV | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS M… | Patch first | 9.8 critical | 11.6% | 2022-03-18 |
| CVE-2022-20821 KEV | A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is… | Patch first | 6.5 medium | 11.5% | 2022-05-26 |
| CVE-2021-27103 KEV | Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later. | Patch first | 9.8 critical | 11.4% | 2021-02-16 |
| CVE-2025-48927 KEV | The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the… | Patch first | 5.3 medium | 11.1% | 2025-05-28 |
| CVE-2022-41328 KEV | A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.… | Patch first | 6.7 medium | 10.7% | 2023-03-07 |
| CVE-2020-15069 KEV | Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access.… | Patch first | 9.8 critical | 10.7% | 2020-06-29 |
| CVE-2022-41223 KEV | The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attac… | Patch first | 6.8 medium | 10.7% | 2022-11-22 |
| CVE-2022-40765 KEV | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal… | Patch first | 6.8 medium | 10.6% | 2022-11-22 |
| CVE-2025-6543 KEV | Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gatew… | Patch first | 9.8 critical | 10.6% | 2025-06-25 |
| CVE-2022-2586 KEV | It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was… | Patch first | 5.3 medium | 10.2% | 2024-01-08 |
| CVE-2026-63030 KEV | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__no… | Patch first | 9.8 critical | 10.1% | 2026-07-17 |
| CVE-2024-6047 KEV | Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vul… | Patch first | 9.8 critical | 10.1% | 2024-06-17 |
| CVE-2024-38217 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 10% | 2024-09-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt