CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,579 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
205,481 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-26486 KEV | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the… | Patch first | 9.6 critical | 2.3% | 2022-12-22 |
| CVE-2023-20109 KEV | A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authentica… | Patch first | 6.6 medium | 2.3% | 2023-09-27 |
| CVE-2025-53521 KEV | When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Softwa… | Patch first | 9.8 critical | 2.3% | 2025-10-15 |
| CVE-2026-94127 KEV | When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution… | Patch first | 9.8 critical | 2.2% | 2026-09-22 |
| CVE-2020-9819 KEV | A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, wa… | Patch first | 4.3 medium | 2.2% | 2020-06-09 |
| CVE-2017-12232 KEV | A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through… | Patch first | 6.5 medium | 2.2% | 2017-09-29 |
| CVE-2017-6663 KEV | A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker… | Patch first | 6.5 medium | 2.1% | 2017-08-07 |
| CVE-2026-49869 KEV | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().e… | Patch first | 10.0 critical | 2.1% | 2026-06-26 |
| CVE-2026-45247 KEV | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attacke… | Patch first | 9.8 critical | 2.1% | 2026-05-26 |
| CVE-2023-6448 KEV | Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacke… | Patch first | 9.8 critical | 2.1% | 2023-12-05 |
| CVE-2017-12238 KEV | A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an u… | Patch first | 6.5 medium | 2% | 2017-09-29 |
| CVE-2025-0111 KEV | An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the manage… | Patch first | 6.5 medium | 2% | 2025-02-12 |
| CVE-2025-24991 KEV | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | Patch first | 5.5 medium | 2% | 2025-03-11 |
| CVE-2025-24984 KEV | Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. | Patch first | 4.6 medium | 2% | 2025-03-11 |
| CVE-2025-59689 KEV | Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.3… | Patch first | 6.1 medium | 1.9% | 2025-09-19 |
| CVE-2026-86060 KEV | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted… | Patch first | 9.8 critical | 1.8% | 2026-09-05 |
| CVE-2022-41091 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 1.8% | 2022-11-09 |
| CVE-2026-34909 KEV | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying… | Patch first | 10.0 critical | 1.8% | 2026-05-22 |
| CVE-2025-21590 KEV | An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to… | Patch first | 4.4 medium | 1.7% | 2025-03-12 |
| CVE-2025-48700 KEV | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Class… | Patch first | 6.1 medium | 1.7% | 2025-06-23 |
| CVE-2026-72530 KEV | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, a… | Patch first | 9.0 critical | 1.7% | 2026-08-19 |
| CVE-2024-39891 KEV | In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain p… | Patch first | 5.3 medium | 1.7% | 2024-07-02 |
| CVE-2026-33824 KEV | Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. | Patch first | 9.8 critical | 1.6% | 2026-04-14 |
| CVE-2025-22224 KEV | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with l… | Patch first | 9.3 critical | 1.6% | 2025-03-04 |
| CVE-2026-72529 KEV | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, a… | Patch first | 9.8 critical | 1.5% | 2026-08-19 |
| CVE-2026-48027 KEV | Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed… | Patch first | 9.8 critical | 1.3% | 2026-05-27 |
| CVE-2025-35939 KEV | Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an… | Patch first | 5.3 medium | 1.3% | 2025-05-07 |
| CVE-2026-45498 KEV | Microsoft Defender Denial of Service Vulnerability | Patch first | 4.0 medium | 1.3% | 2026-05-20 |
| CVE-2026-65400 KEV | An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma… | Patch first | 9.8 critical | 1.2% | 2026-08-06 |
| CVE-2025-59374 KEV | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supp… | Patch first | 9.8 critical | 1.2% | 2025-12-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt