CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,558 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,469 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-27101 KEV | Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA… | Patch first | 9.8 critical | 6% | 2021-02-16 |
| CVE-2026-60137 KEV | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which co… | Patch first | 5.9 medium | 5.9% | 2026-07-17 |
| CVE-2019-6693 KEV | Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup fi… | Patch first | 6.5 medium | 5.8% | 2019-11-21 |
| CVE-2026-42208 KEV | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query… | Patch first | 9.8 critical | 5.8% | 2026-05-08 |
| CVE-2022-3075 KEV | Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to po… | Patch first | 9.6 critical | 5.8% | 2022-09-26 |
| CVE-2023-2136 KEV | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially pe… | Patch first | 9.6 critical | 5.7% | 2023-04-19 |
| CVE-2026-48558 KEV | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When… | Patch first | 10.0 critical | 5.7% | 2026-06-12 |
| CVE-2022-20700 KEV | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch first | 10.0 critical | 5.7% | 2022-02-10 |
| CVE-2025-10585 KEV | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… | Patch first | 9.8 critical | 5.4% | 2025-09-24 |
| CVE-2017-12319 KEV | A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthen… | Patch first | 5.9 medium | 5.2% | 2018-03-27 |
| CVE-2019-16256 KEV | Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location an… | Patch first | 9.8 critical | 4.9% | 2019-09-12 |
| CVE-2021-38000 KEV | Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily brows… | Patch first | 6.1 medium | 4.9% | 2021-11-23 |
| CVE-2018-0179 KEV | Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trig… | Patch first | 5.9 medium | 4.9% | 2018-03-28 |
| CVE-2018-0180 KEV | Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trig… | Patch first | 5.9 medium | 4.9% | 2018-03-28 |
| CVE-2025-47827 KEV | In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a cr… | Patch first | 4.6 medium | 4.9% | 2025-06-05 |
| CVE-2004-1464 KEV | Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP co… | Patch first | 5.9 medium | 4.8% | 2004-12-31 |
| CVE-2026-21525 KEV | Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. | Patch first | 6.2 medium | 4.8% | 2026-02-10 |
| CVE-2013-3993 KEV | IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted da… | Patch first | 6.5 medium | 4.8% | 2014-07-07 |
| CVE-2012-0518 KEV | Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to… | Patch first | 4.7 medium | 4.7% | 2012-10-16 |
| CVE-2020-29574 KEV | An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements… | Patch first | 9.8 critical | 4.7% | 2020-12-11 |
| CVE-2022-2856 KEV | Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily bro… | Patch first | 6.5 medium | 4.5% | 2022-09-26 |
| CVE-2026-81578 KEV | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthentic… | Patch first | 9.8 critical | 4.5% | 2026-08-28 |
| CVE-2025-24200 KEV | An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.… | Patch first | 6.1 medium | 4.5% | 2025-02-10 |
| CVE-2020-2021 KEV | When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecke… | Patch first | 10.0 critical | 4.4% | 2020-06-29 |
| CVE-2024-20399 KEV | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary c… | Patch first | 6.0 medium | 4.3% | 2024-07-01 |
| CVE-2025-55177 KEV | Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, an… | Patch first | 5.4 medium | 4.3% | 2025-08-29 |
| CVE-2021-20035 KEV | Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as… | Patch first | 6.5 medium | 4.2% | 2021-09-27 |
| CVE-2018-0161 KEV | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches… | Patch first | 6.3 medium | 4.1% | 2018-03-28 |
| CVE-2022-26501 KEV | Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). | Patch first | 9.8 critical | 4.1% | 2022-03-17 |
| CVE-2015-1769 KEV | Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and… | Patch first | 6.6 medium | 4.1% | 2015-08-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt