CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,558 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,469 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-3055 KEV | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | Patch first | 9.8 critical | 4% | 2026-03-23 |
| CVE-2025-27915 KEV | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic W… | Patch first | 5.4 medium | 4% | 2025-03-12 |
| CVE-2026-75650 KEV | Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary co… | Patch first | 10.0 critical | 3.9% | 2026-09-07 |
| CVE-2026-82078 KEV | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates… | Patch first | 9.1 critical | 3.8% | 2026-08-28 |
| CVE-2024-9537 KEV | ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vuln… | Patch first | 9.8 critical | 3.8% | 2024-10-18 |
| CVE-2025-24201 KEV | An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and… | Patch first | 10.0 critical | 3.8% | 2025-03-11 |
| CVE-2021-35247 KEV | Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanis… | Patch first | 4.3 medium | 3.5% | 2022-01-10 |
| CVE-2009-2055 KEV | Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribu… | Patch first | 5.9 medium | 3.3% | 2009-08-19 |
| CVE-2025-42599 KEV | Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request create… | Patch first | 9.8 critical | 3.3% | 2025-04-18 |
| CVE-2020-9934 KEV | An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPad… | Patch first | 5.5 medium | 3.2% | 2020-10-16 |
| CVE-2023-6548 KEV | Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP… | Patch first | 5.5 medium | 3.2% | 2024-01-17 |
| CVE-2021-27562 KEV | In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when ca… | Patch first | 5.5 medium | 3.1% | 2021-05-25 |
| CVE-2011-4723 KEV | The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors… | Patch first | 5.7 medium | 3.1% | 2011-12-20 |
| CVE-2023-36584 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 3.1% | 2023-10-10 |
| CVE-2026-50522 KEV | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | Patch first | 9.8 critical | 3% | 2026-07-14 |
| CVE-2021-31199 KEV | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | Patch first | 5.2 medium | 3% | 2021-06-08 |
| CVE-2023-38606 KEV | This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPad… | Patch first | 5.5 medium | 2.9% | 2023-07-27 |
| CVE-2025-39682 KEV | In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must… | Patch first | 9.8 critical | 2.9% | 2025-09-05 |
| CVE-2021-25337 KEV | Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write… | Patch first | 4.4 medium | 2.8% | 2021-03-04 |
| CVE-2025-61932 KEV | Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing a… | Patch first | 9.8 critical | 2.8% | 2025-10-20 |
| CVE-2025-40602 KEV | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). | Patch first | 6.6 medium | 2.8% | 2025-12-18 |
| CVE-2020-16017 KEV | Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potenti… | Patch first | 9.6 critical | 2.7% | 2021-01-08 |
| CVE-2022-42948 KEV | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to… | Patch first | 9.8 critical | 2.7% | 2023-03-24 |
| CVE-2020-0878 KEV | <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in… | Patch first | 4.2 medium | 2.7% | 2020-09-11 |
| CVE-2023-29492 KEV | Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not prov… | Patch first | 9.8 critical | 2.7% | 2023-04-11 |
| CVE-2021-31201 KEV | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | Patch first | 5.2 medium | 2.6% | 2021-06-08 |
| CVE-2026-59310 KEV | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this is… | Patch first | 9.8 critical | 2.6% | 2026-07-30 |
| CVE-2023-21492 KEV | Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. | Patch first | 4.4 medium | 2.6% | 2023-05-04 |
| CVE-2022-41049 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 2.5% | 2022-11-09 |
| CVE-2025-32975 KEV | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5),… | Patch first | 10.0 critical | 2.5% | 2025-06-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt