CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,587 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
205,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-43520 KEV | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1,… | Patch first | 5.5 medium | 0.4% | 2025-12-12 |
| CVE-2021-25394 KEV | A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege… | Patch first | 6.4 medium | 0.4% | 2021-06-11 |
| CVE-2022-22265 KEV | An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution… | Patch first | 5.0 medium | 0.4% | 2022-01-10 |
| CVE-2021-25395 KEV | A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is com… | Patch first | 6.4 medium | 0.4% | 2021-06-11 |
| CVE-2023-21237 KEV | In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insuffici… | Patch first | 5.5 medium | 0.3% | 2023-06-28 |
| CVE-2025-48633 KEV | In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in t… | Patch first | 5.5 medium | 0.3% | 2025-12-08 |
| CVE-2022-42889 EXP | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolati… | Patch early | 9.8 critical | 99.9% | 2022-10-13 |
| CVE-2017-12635 EXP | Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.… | Patch early | 9.8 critical | 99.8% | 2017-11-14 |
| CVE-2017-8917 EXP | SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors. | Patch early | 9.8 critical | 99.8% | 2017-05-17 |
| CVE-2008-2938 EXP | Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 a… | Patch early | 4.3 medium | 99.7% | 2008-08-13 |
| CVE-2020-10220 EXP | An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter. | Patch early | 9.8 critical | 99.7% | 2020-03-07 |
| CVE-2023-27372 EXP | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,… | Patch early | 9.8 critical | 99.7% | 2023-02-28 |
| CVE-2022-37061 EXP | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject an… | Patch early | 9.8 critical | 99.6% | 2022-08-18 |
| CVE-2020-14181 EXP | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabilit… | Patch early | 5.3 medium | 99.6% | 2020-09-17 |
| CVE-2020-16040 EXP | Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a craft… | Patch early | 6.5 medium | 99.6% | 2021-01-08 |
| CVE-2014-0094 EXP | The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is p… | Patch early | 5.0 medium | 99.6% | 2014-03-11 |
| CVE-2023-32560 EXP | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code executi… | Patch early | 9.8 critical | 99.4% | 2023-08-10 |
| CVE-2025-1974 EXP | A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve a… | Patch early | 9.8 critical | 99.4% | 2025-03-25 |
| CVE-2021-34429 EXP | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of th… | Patch early | 5.3 medium | 99.3% | 2021-07-15 |
| CVE-2017-12542 EXP | A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found. | Patch early | 10.0 critical | 99.3% | 2018-02-15 |
| CVE-2023-23333 EXP | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions throug… | Patch early | 9.8 critical | 99.3% | 2023-02-06 |
| CVE-2025-29927 EXP | Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 1… | Patch early | 9.1 critical | 99.2% | 2025-03-21 |
| CVE-2020-11022 EXP | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation… | Patch early | 6.9 medium | 99.2% | 2020-04-29 |
| CVE-2022-24637 EXP | Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin… | Patch early | 9.8 critical | 99.1% | 2022-03-18 |
| CVE-2020-9496 EXP | XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 | Patch early | 6.1 medium | 98.9% | 2020-07-15 |
| CVE-2020-7209 EXP | LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2. | Patch early | 9.8 critical | 98.8% | 2020-02-13 |
| CVE-2018-19276 EXP | OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary command… | Patch early | 9.8 critical | 98.7% | 2019-03-21 |
| CVE-2018-15473 EXP | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet… | Patch early | 5.3 medium | 98.6% | 2018-08-17 |
| CVE-2018-11409 EXP | Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by… | Patch early | 5.3 medium | 98.3% | 2018-06-08 |
| CVE-2020-15920 EXP | There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (… | Patch early | 9.8 critical | 98.2% | 2020-07-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt