CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,558 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
148,908 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-8068 KEV | Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active… | Patch first | 8.0 high | 3.5% | 2024-11-12 |
| CVE-2018-0175 KEV | Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Softw… | Patch first | 8.0 high | 3.5% | 2018-03-28 |
| CVE-2019-1315 KEV | An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manage… | Patch first | 7.8 high | 3.5% | 2019-10-10 |
| CVE-2025-8876 KEV | Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. | Patch first | 8.8 high | 3.4% | 2025-08-14 |
| CVE-2018-8406 KEV | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Gr… | Patch first | 7.8 high | 3.4% | 2018-08-15 |
| CVE-2018-8405 KEV | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Gr… | Patch first | 7.8 high | 3.4% | 2018-08-15 |
| CVE-2026-31431 KEV | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit… | Patch first | 7.8 high | 3.4% | 2026-04-22 |
| CVE-2025-66644 KEV | Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. | Patch first | 7.2 high | 3.4% | 2025-12-05 |
| CVE-2024-53104 KEV | In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format… | Patch first | 7.8 high | 3.4% | 2024-12-02 |
| CVE-2018-0167 KEV | Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco… | Patch first | 8.8 high | 3.4% | 2018-03-28 |
| CVE-2020-3569 KEV | Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, re… | Patch first | 8.6 high | 3.3% | 2020-09-23 |
| CVE-2022-40139 KEV | Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allo… | Patch first | 7.2 high | 3.3% | 2022-09-19 |
| CVE-2022-32894 KEV | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1.… | Patch first | 7.8 high | 3.3% | 2022-08-24 |
| CVE-2022-48503 KEV | The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Saf… | Patch first | 8.8 high | 3.2% | 2023-08-14 |
| CVE-2013-2596 KEV | Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1… | Patch first | 7.8 high | 3.2% | 2013-04-13 |
| CVE-2020-9907 KEV | A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application… | Patch first | 7.8 high | 3.2% | 2020-10-16 |
| CVE-2020-0041 KEV | In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of pr… | Patch first | 7.8 high | 3.1% | 2020-03-10 |
| CVE-2026-87491 KEV | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted… | Patch first | 8.8 high | 3.1% | 2026-09-09 |
| CVE-2017-0001 KEV | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 201… | Patch first | 7.8 high | 3.1% | 2017-03-17 |
| CVE-2021-43226 KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Patch first | 7.8 high | 3.1% | 2021-12-15 |
| CVE-2022-41125 KEV | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | Patch first | 7.8 high | 3% | 2022-11-09 |
| CVE-2020-6819 KEV | Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the… | Patch first | 8.1 high | 3% | 2020-04-24 |
| CVE-2018-8589 KEV | An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnera… | Patch first | 7.8 high | 3% | 2018-11-14 |
| CVE-2021-30666 KEV | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may… | Patch first | 8.8 high | 3% | 2021-09-08 |
| CVE-2021-29256 KEV | . The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege es… | Patch first | 8.8 high | 3% | 2021-05-24 |
| CVE-2024-32896 KEV | there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pri… | Patch first | 7.8 high | 3% | 2024-06-13 |
| CVE-2024-7262 KEV | Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows all… | Patch first | 7.8 high | 2.9% | 2024-08-15 |
| CVE-2024-11667 KEV | A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmwar… | Patch first | 7.5 high | 2.9% | 2024-11-27 |
| CVE-2021-30983 KEV | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to ex… | Patch first | 7.8 high | 2.9% | 2021-08-24 |
| CVE-2021-38649 KEV | Open Management Infrastructure Elevation of Privilege Vulnerability | Patch first | 7.0 high | 2.9% | 2021-09-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt