CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,553 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
398,553 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-43451 KEV | NTLM Hash Disclosure Spoofing Vulnerability | Patch first | 6.5 medium | 84.1% | 2024-11-12 |
| CVE-2023-28432 KEV | Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20… | Patch first | 7.5 high | 84% | 2023-03-22 |
| CVE-2015-3035 KEV | Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firm… | Patch first | 7.5 high | 83.9% | 2015-04-22 |
| CVE-2019-9874 KEV | Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allow… | Patch first | 9.8 critical | 83.7% | 2019-05-31 |
| CVE-2019-0193 KEV | In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the who… | Patch first | 7.2 high | 83.5% | 2019-08-01 |
| CVE-2022-26923 KEV | Active Directory Domain Services Elevation of Privilege Vulnerability | Patch first | 8.8 high | 83.5% | 2022-05-10 |
| CVE-2023-36847 KEV | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attack… | Patch first | 5.3 medium | 83.5% | 2023-08-17 |
| CVE-2024-21762 KEV | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through… | Patch first | 9.8 critical | 83.4% | 2024-02-09 |
| CVE-2025-14847 KEV | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue af… | Patch first | 7.5 high | 83.2% | 2025-12-19 |
| CVE-2019-7194 KEV | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP reco… | Patch first | 9.8 critical | 83.1% | 2019-12-05 |
| CVE-2022-24990 KEV | TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mob… | Patch first | 7.5 high | 83% | 2023-02-07 |
| CVE-2020-3992 KEV | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-… | Patch first | 9.8 critical | 83% | 2020-10-20 |
| CVE-2024-42009 KEV | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim… | Patch first | 9.3 critical | 82.9% | 2024-08-05 |
| CVE-2021-27561 KEV | Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication. | Patch first | 9.8 critical | 82.9% | 2021-10-15 |
| CVE-2023-27992 KEV | The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior… | Patch first | 9.8 critical | 82.8% | 2023-06-19 |
| CVE-2024-0769 KEV | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unk… | Patch first | 5.3 medium | 82.7% | 2024-01-21 |
| CVE-2023-43208 KEV | NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused b… | Patch first | 9.8 critical | 82.7% | 2023-10-26 |
| CVE-2014-1776 KEV | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of servic… | Patch first | 9.8 critical | 82.7% | 2014-04-27 |
| CVE-2021-23758 KEV | All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET clas… | Patch first | 8.1 high | 82.6% | 2021-12-03 |
| CVE-2025-34026 KEV | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at att… | Patch first | 7.5 high | 81.9% | 2025-05-21 |
| CVE-2023-27532 KEV | Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead… | Patch first | 7.5 high | 81.3% | 2023-03-10 |
| CVE-2017-11826 KEV | Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer,… | Patch first | 7.8 high | 81.2% | 2017-10-13 |
| CVE-2021-31955 KEV | Windows Kernel Information Disclosure Vulnerability | Patch first | 5.5 medium | 81.1% | 2021-06-08 |
| CVE-2017-0262 KEV | Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle obj… | Patch first | 7.8 high | 81% | 2017-05-12 |
| CVE-2024-43468 KEV | Microsoft Configuration Manager Remote Code Execution Vulnerability | Patch first | 9.8 critical | 80.9% | 2024-10-08 |
| CVE-2021-26411 KEV | Internet Explorer Memory Corruption Vulnerability | Patch first | 8.8 high | 80.8% | 2021-03-11 |
| CVE-2023-22952 KEV | In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. | Patch first | 8.8 high | 80.1% | 2023-01-11 |
| CVE-2013-1331 KEV | Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Offi… | Patch first | 7.8 high | 79.8% | 2013-06-12 |
| CVE-2020-10987 KEV | The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceN… | Patch first | 9.8 critical | 79.8% | 2020-07-13 |
| CVE-2024-8957 KEV | PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_ad… | Patch first | 7.2 high | 79.7% | 2024-09-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt