CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,553 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
148,906 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-30554 KEV | Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa… | Patch first | 8.8 high | 7.4% | 2021-07-02 |
| CVE-2017-6744 KEV | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authent… | Patch first | 8.8 high | 7.3% | 2017-07-17 |
| CVE-2025-24472 KEV | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 throug… | Patch first | 8.1 high | 7.2% | 2025-02-11 |
| CVE-2018-0158 KEV | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,… | Patch first | 8.6 high | 7.2% | 2018-03-28 |
| CVE-2024-38080 KEV | Windows Hyper-V Elevation of Privilege Vulnerability | Patch first | 7.8 high | 7.1% | 2024-07-09 |
| CVE-2022-24521 KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Patch first | 7.8 high | 7.1% | 2022-04-15 |
| CVE-2017-12233 KEV | Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthent… | Patch first | 7.5 high | 7.1% | 2017-09-29 |
| CVE-2017-12234 KEV | Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthent… | Patch first | 7.5 high | 7.1% | 2017-09-29 |
| CVE-2017-12235 KEV | A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an una… | Patch first | 7.5 high | 7.1% | 2017-09-29 |
| CVE-2017-12237 KEV | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an… | Patch first | 7.5 high | 7.1% | 2017-09-29 |
| CVE-2018-0154 KEV | A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticat… | Patch first | 7.5 high | 7.1% | 2018-03-28 |
| CVE-2017-12231 KEV | A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated… | Patch first | 7.5 high | 7.1% | 2017-09-29 |
| CVE-2026-20128 KEV | A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DC… | Patch first | 7.5 high | 7.1% | 2026-02-25 |
| CVE-2020-6820 KEV | Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild ab… | Patch first | 8.1 high | 7.1% | 2020-04-24 |
| CVE-2021-30713 KEV | A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass P… | Patch first | 7.8 high | 7% | 2021-09-08 |
| CVE-2021-30952 KEV | An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPa… | Patch first | 7.8 high | 7% | 2021-08-24 |
| CVE-2019-1064 KEV | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfu… | Patch first | 7.8 high | 6.9% | 2019-06-12 |
| CVE-2018-0159 KEV | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could a… | Patch first | 7.5 high | 6.9% | 2018-03-28 |
| CVE-2023-26369 KEV | Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write v… | Patch first | 7.8 high | 6.7% | 2023-09-13 |
| CVE-2023-7024 KEV | Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted… | Patch first | 8.8 high | 6.7% | 2023-12-21 |
| CVE-2026-34486 KEV | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.… | Patch first | 7.5 high | 6.6% | 2026-04-09 |
| CVE-2021-33739 KEV | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Patch first | 8.4 high | 6.6% | 2021-06-08 |
| CVE-2025-24990 KEV | Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an… | Patch first | 7.8 high | 6.4% | 2025-10-14 |
| CVE-2024-38106 KEV | Windows Kernel Elevation of Privilege Vulnerability | Patch first | 7.0 high | 6.3% | 2024-08-13 |
| CVE-2024-38014 KEV | Windows Installer Elevation of Privilege Vulnerability | Patch first | 7.8 high | 6.3% | 2024-09-10 |
| CVE-2020-8468 KEV | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulner… | Patch first | 8.8 high | 6.2% | 2020-03-18 |
| CVE-2017-6627 KEV | A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attac… | Patch first | 7.5 high | 6.2% | 2017-09-07 |
| CVE-2019-1069 KEV | An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully e… | Patch first | 7.8 high | 6.1% | 2019-06-12 |
| CVE-2021-27059 KEV | Microsoft Office Remote Code Execution Vulnerability | Patch first | 7.6 high | 6.1% | 2021-03-11 |
| CVE-2022-26500 KEV | Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API f… | Patch first | 8.8 high | 5.8% | 2022-03-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt