CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,579 CVEs
1,726 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
185,367 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-2294 KEV | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted… | Patch first | 8.8 high | 70.5% | 2022-07-28 |
| CVE-2021-21220 KEV | Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corrupt… | Patch first | 8.8 high | 70.4% | 2021-04-26 |
| CVE-2020-4427 KEV | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with… | Patch first | 9.8 critical | 70% | 2020-05-07 |
| CVE-2021-44026 KEV | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. | Patch first | 9.8 critical | 69.9% | 2021-11-19 |
| CVE-2016-0034 KEV | Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cau… | Patch first | 8.8 high | 69.4% | 2016-01-13 |
| CVE-2020-0938 KEV | A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted m… | Patch first | 7.8 high | 69% | 2020-04-15 |
| CVE-2016-11021 KEV | setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter. | Patch first | 7.2 high | 68.9% | 2020-03-09 |
| CVE-2016-3393 KEV | Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Se… | Patch first | 7.8 high | 68.5% | 2016-10-14 |
| CVE-2025-59718 KEV | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 t… | Patch first | 9.8 critical | 68.3% | 2025-12-09 |
| CVE-2024-30088 KEV | Windows Kernel Elevation of Privilege Vulnerability | Patch first | 7.0 high | 68.2% | 2024-06-11 |
| CVE-2023-28461 KEV | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gate… | Patch first | 9.8 critical | 68.1% | 2023-03-15 |
| CVE-2025-20337 KEV | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the unde… | Patch first | 10.0 critical | 67.8% | 2025-07-16 |
| CVE-2022-34713 KEV | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | Patch first | 7.8 high | 67.8% | 2022-08-09 |
| CVE-2015-8651 KEV | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Ado… | Patch first | 8.8 high | 67.7% | 2015-12-28 |
| CVE-2009-0556 KEV | Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbi… | Patch first | 8.8 high | 67.3% | 2009-04-03 |
| CVE-2021-36934 KEV | An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Securi… | Patch first | 7.8 high | 67.3% | 2021-07-22 |
| CVE-2025-0411 KEV | 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected… | Patch first | 7.0 high | 67.1% | 2025-01-25 |
| CVE-2024-43572 KEV | Microsoft Management Console Remote Code Execution Vulnerability | Patch first | 7.8 high | 66.7% | 2024-10-08 |
| CVE-2024-57726 KEV | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive perm… | Patch first | 9.9 critical | 66.6% | 2025-01-15 |
| CVE-2013-0631 KEV | Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2… | Patch first | 7.5 high | 66.4% | 2013-01-09 |
| CVE-2021-36942 KEV | Windows LSA Spoofing Vulnerability | Patch first | 7.5 high | 66% | 2021-08-12 |
| CVE-2020-1020 KEV | A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted m… | Patch first | 8.8 high | 65% | 2020-04-15 |
| CVE-2021-27877 KEV | An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This auth… | Patch first | 8.2 high | 64.9% | 2021-03-01 |
| CVE-2014-1812 KEV | The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows… | Patch first | 8.8 high | 64.9% | 2014-05-14 |
| CVE-2021-30551 KEV | Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Patch first | 8.8 high | 64.7% | 2021-06-15 |
| CVE-2024-57728 KEV | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted z… | Patch first | 7.2 high | 64.7% | 2025-01-15 |
| CVE-2016-7256 KEV | atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2… | Patch first | 8.8 high | 64.6% | 2016-11-10 |
| CVE-2025-2776 KEV | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functiona… | Patch first | 9.3 critical | 64.4% | 2025-05-07 |
| CVE-2016-20017 KEV | D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016… | Patch first | 9.8 critical | 64.2% | 2022-10-19 |
| CVE-2023-29552 KEV | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker… | Patch first | 7.5 high | 64% | 2023-04-25 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt