CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,587 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
185,371 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2015-4068 KEV | Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of ser… | Patch first | 9.1 critical | 63.6% | 2015-05-29 |
| CVE-2021-22681 KEV | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers ar… | Patch first | 9.8 critical | 63.6% | 2021-03-03 |
| CVE-2023-35081 KEV | A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated adminis… | Patch first | 7.2 high | 63.6% | 2023-08-03 |
| CVE-2021-30632 KEV | Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p… | Patch first | 8.8 high | 63.2% | 2021-10-08 |
| CVE-2009-0563 KEV | Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File F… | Patch first | 7.8 high | 62.8% | 2009-06-10 |
| CVE-2022-21445 KEV | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions th… | Patch first | 9.8 critical | 62.5% | 2022-04-19 |
| CVE-2025-62593 KEV | Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerabil… | Patch first | 8.8 high | 62.5% | 2025-11-26 |
| CVE-2010-1428 KEV | The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 b… | Patch first | 7.5 high | 62.1% | 2010-04-28 |
| CVE-2018-8373 KEV | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engin… | Patch first | 7.5 high | 61.9% | 2018-08-15 |
| CVE-2024-23113 KEV | A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy v… | Patch first | 9.8 critical | 61.7% | 2024-02-15 |
| CVE-2020-4428 KEV | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Fo… | Patch first | 9.1 critical | 61.7% | 2020-05-07 |
| CVE-2018-4939 KEV | Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vul… | Patch first | 9.8 critical | 61.7% | 2018-05-19 |
| CVE-2023-21608 KEV | Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free v… | Patch first | 7.8 high | 61.5% | 2023-01-18 |
| CVE-2015-7755 KEV | Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b… | Patch first | 9.8 critical | 61.1% | 2015-12-19 |
| CVE-2021-22991 KEV | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclos… | Patch first | 9.8 critical | 61.1% | 2021-03-31 |
| CVE-2024-54085 KEV | AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful ex… | Patch first | 9.8 critical | 60.7% | 2025-03-11 |
| CVE-2025-58360 KEV | GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML… | Patch first | 8.2 high | 60.5% | 2025-11-25 |
| CVE-2014-4148 KEV | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind… | Patch first | 8.8 high | 59.9% | 2014-10-15 |
| CVE-2024-9380 KEV | An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin pr… | Patch first | 7.2 high | 59.7% | 2024-10-08 |
| CVE-2017-11774 KEV | Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office… | Patch first | 7.8 high | 59.6% | 2017-10-13 |
| CVE-2021-33742 KEV | Windows MSHTML Platform Remote Code Execution Vulnerability | Patch first | 7.5 high | 59.4% | 2021-06-08 |
| CVE-2023-21529 KEV | Microsoft Exchange Server Remote Code Execution Vulnerability | Patch first | 8.8 high | 59.3% | 2023-02-14 |
| CVE-2022-21882 KEV | Win32k Elevation of Privilege Vulnerability | Patch first | 7.0 high | 59.2% | 2022-01-11 |
| CVE-2024-8956 KEV | PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authenti… | Patch first | 9.1 critical | 58.8% | 2024-09-17 |
| CVE-2010-2572 KEV | Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document,… | Patch first | 7.8 high | 58.6% | 2010-11-10 |
| CVE-2019-1068 KEV | A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL… | Patch first | 8.8 high | 57.9% | 2019-07-15 |
| CVE-2016-7262 KEV | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-as… | Patch first | 7.8 high | 57.7% | 2016-12-20 |
| CVE-2023-6549 KEV | Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Servic… | Patch first | 8.2 high | 57.6% | 2024-01-17 |
| CVE-2016-7193 KEV | Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack… | Patch first | 7.8 high | 57.6% | 2016-10-14 |
| CVE-2020-26919 KEV | NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level. | Patch first | 9.8 critical | 57.5% | 2020-10-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt