CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,553 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
398,558 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-18809 KEV | The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperRep… | Patch first | 6.5 medium | 79.1% | 2019-03-07 |
| CVE-2023-49103 KEV | An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.p… | Patch first | 10.0 critical | 78.4% | 2023-11-21 |
| CVE-2021-1732 KEV | Windows Win32k Elevation of Privilege Vulnerability | Patch first | 7.8 high | 78.4% | 2021-02-25 |
| CVE-2021-21975 KEV | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vR… | Patch first | 7.5 high | 78.3% | 2021-03-31 |
| CVE-2021-28799 KEV | An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allo… | Patch first | 10.0 critical | 78.3% | 2021-05-13 |
| CVE-2022-26318 KEV | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS be… | Patch first | 9.8 critical | 78.2% | 2022-03-04 |
| CVE-2011-3402 KEV | Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Se… | Patch first | 8.8 high | 78.1% | 2011-11-04 |
| CVE-2017-0261 KEV | Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle obj… | Patch first | 7.8 high | 78.1% | 2017-05-12 |
| CVE-2023-27351 KEV | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is n… | Patch first | 7.5 high | 78.1% | 2023-04-20 |
| CVE-2023-24880 KEV | Windows SmartScreen Security Feature Bypass Vulnerability | Patch first | 4.4 medium | 78% | 2023-03-14 |
| CVE-2026-16232 KEV | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicatio… | Patch first | 9.8 critical | 78% | 2026-07-22 |
| CVE-2025-6204 KEV | An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an… | Patch first | 8.0 high | 78% | 2025-08-04 |
| CVE-2026-8037 KEV | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary comm… | Patch first | 9.6 critical | 77.4% | 2026-06-04 |
| CVE-2022-41080 KEV | Microsoft Exchange Server Elevation of Privilege Vulnerability | Patch first | 8.8 high | 77.3% | 2022-11-09 |
| CVE-2023-34192 KEV | Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the… | Patch first | 9.0 critical | 77.3% | 2023-07-06 |
| CVE-2021-42287 KEV | Active Directory Domain Services Elevation of Privilege Vulnerability | Patch first | 7.5 high | 77.2% | 2021-11-10 |
| CVE-2019-7238 KEV | Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control. | Patch first | 9.8 critical | 77.1% | 2019-03-21 |
| CVE-2020-13965 KEV | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is amo… | Patch first | 6.1 medium | 76.6% | 2020-06-09 |
| CVE-2021-38406 KEV | Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could r… | Patch first | 7.8 high | 76.4% | 2021-09-17 |
| CVE-2022-44698 KEV | Windows SmartScreen Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 76.3% | 2022-12-13 |
| CVE-2023-44221 KEV | Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative priv… | Patch first | 7.2 high | 76.3% | 2023-12-05 |
| CVE-2026-25089 KEV | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.… | Patch first | 9.8 critical | 76.1% | 2026-06-09 |
| CVE-2021-30860 KEV | An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8,… | Patch first | 7.8 high | 76% | 2021-08-24 |
| CVE-2023-5631 KEV | Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because o… | Patch first | 6.1 medium | 75.9% | 2023-10-18 |
| CVE-2021-25298 KEV | Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/c… | Patch first | 8.8 high | 75.1% | 2021-02-15 |
| CVE-2025-1316 KEV | Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device | Patch first | 9.8 critical | 74.5% | 2025-03-05 |
| CVE-2021-42258 KEV | BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in… | Patch first | 9.8 critical | 74.4% | 2021-10-22 |
| CVE-2018-14667 KEV | The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated… | Patch first | 9.8 critical | 74.2% | 2018-11-06 |
| CVE-2017-8543 KEV | Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Wi… | Patch first | 9.8 critical | 74.2% | 2017-06-15 |
| CVE-2024-21182 KEV | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.… | Patch first | 7.5 high | 74.2% | 2024-07-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt