CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,436 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-26
317,842 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-6332 KEV EXP | OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1… | Patch first | 8.8 high | 95% | 2014-11-11 |
| CVE-2017-9822 KEV EXP | DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." | Patch first | 8.8 high | 94.8% | 2017-07-20 |
| CVE-2021-4034 KEV EXP | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivilege… | Patch first | 7.8 high | 94.3% | 2022-01-28 |
| CVE-2016-0189 KEV EXP | The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attacke… | Patch first | 7.5 high | 94.1% | 2016-05-11 |
| CVE-2020-1147 KEV EXP | A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source ma… | Patch first | 7.8 high | 94% | 2020-07-14 |
| CVE-2017-0143 KEV EXP | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Wind… | Patch first | 8.8 high | 93.3% | 2017-03-17 |
| CVE-2020-5849 KEV EXP | Unraid 6.8.0 allows authentication bypass. | Patch first | 7.5 high | 93.2% | 2020-03-16 |
| CVE-2022-0847 KEV EXP | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_p… | Patch first | 7.8 high | 92.8% | 2022-03-10 |
| CVE-2022-43939 KEV EXP | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonic… | Patch first | 8.6 high | 92.3% | 2023-04-03 |
| CVE-2019-2616 KEV EXP | Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported vers… | Patch first | 7.2 high | 92.2% | 2019-04-23 |
| CVE-2019-6340 KEV EXP | Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to ar… | Patch first | 8.1 high | 92% | 2019-02-21 |
| CVE-2010-0249 KEV EXP | Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; W… | Patch first | 8.8 high | 91.9% | 2010-01-15 |
| CVE-2010-2568 KEV EXP | Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote atta… | Patch first | 7.8 high | 91.3% | 2010-07-22 |
| CVE-2012-0754 KEV EXP | Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x;… | Patch first | 8.1 high | 91.2% | 2012-02-16 |
| CVE-2013-0431 KEV EXP | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted r… | Patch first | 5.3 medium | 90.2% | 2013-01-31 |
| CVE-2009-3960 KEV EXP | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex… | Patch first | 6.5 medium | 90.1% | 2010-02-15 |
| CVE-2017-8464 KEV EXP | Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,… | Patch first | 8.8 high | 89.9% | 2017-06-15 |
| CVE-2017-8570 KEV EXP | Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Exec… | Patch first | 7.8 high | 89.9% | 2017-07-11 |
| CVE-2017-0146 KEV EXP | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Wind… | Patch first | 8.8 high | 89.9% | 2017-03-17 |
| CVE-2017-0145 KEV EXP | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Wind… | Patch first | 8.8 high | 89.9% | 2017-03-17 |
| CVE-2018-15982 KEV EXP | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to ar… | Patch first | 7.8 high | 89.6% | 2019-01-18 |
| CVE-2018-4878 KEV EXP | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Prim… | Patch first | 7.8 high | 89.5% | 2018-02-06 |
| CVE-2010-3333 KEV EXP | Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 20… | Patch first | 7.8 high | 89.5% | 2010-11-10 |
| CVE-2020-0601 KEV EXP | A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could… | Patch first | 8.1 high | 89.4% | 2020-01-14 |
| CVE-2017-5521 KEV EXP | An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices… | Patch first | 8.1 high | 89.2% | 2017-01-17 |
| CVE-2017-8759 KEV EXP | Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or appl… | Patch first | 7.8 high | 88.7% | 2017-09-13 |
| CVE-2014-3120 KEV EXP | The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions a… | Patch first | 8.1 high | 88.6% | 2014-07-28 |
| CVE-2021-43798 KEV EXP | Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vuln… | Patch first | 7.5 high | 88.5% | 2021-12-07 |
| CVE-2018-8174 KEV EXP | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code E… | Patch first | 7.5 high | 88.3% | 2018-05-09 |
| CVE-2010-0188 KEV EXP | Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application… | Patch first | 7.8 high | 88.2% | 2010-02-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt