CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,596 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
185,378 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-26828 KEV | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via v… | Patch first | 8.8 high | 39.4% | 2021-06-11 |
| CVE-2020-1464 KEV | A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could by… | Patch first | 7.8 high | 38.9% | 2020-08-17 |
| CVE-2021-38003 KEV | Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a craft… | Patch first | 8.8 high | 38.6% | 2021-11-23 |
| CVE-2008-0655 KEV | Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors. | Patch first | 8.8 high | 37.9% | 2008-02-07 |
| CVE-2019-11001 KEV | On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to i… | Patch first | 7.2 high | 37.5% | 2019-04-08 |
| CVE-2020-17144 KEV | Microsoft Exchange Remote Code Execution Vulnerability | Patch first | 8.4 high | 36.5% | 2020-12-10 |
| CVE-2018-4990 KEV | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerabil… | Patch first | 8.8 high | 36.2% | 2018-07-09 |
| CVE-2021-38163 KEV | SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user… | Patch first | 9.9 critical | 36% | 2021-09-14 |
| CVE-2022-31199 KEV | Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server a… | Patch first | 9.8 critical | 36% | 2022-11-08 |
| CVE-2018-17480 KEV | Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allo… | Patch first | 8.8 high | 35.6% | 2018-12-11 |
| CVE-2022-22960 KEV | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in supp… | Patch first | 7.8 high | 35.5% | 2022-04-13 |
| CVE-2020-13671 KEV | Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and s… | Patch first | 8.8 high | 35.4% | 2020-11-20 |
| CVE-2015-1770 KEV | Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Unini… | Patch first | 8.8 high | 35% | 2015-06-10 |
| CVE-2021-37975 KEV | Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Patch first | 8.8 high | 34.9% | 2021-10-08 |
| CVE-2015-2387 KEV | ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7… | Patch first | 7.8 high | 34.9% | 2015-07-14 |
| CVE-2016-5198 KEV | V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisatio… | Patch first | 8.8 high | 34.2% | 2017-01-19 |
| CVE-2020-2509 KEV | A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrar… | Patch first | 9.8 critical | 34% | 2021-04-17 |
| CVE-2022-40799 KEV | Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device. | Patch first | 8.8 high | 33.7% | 2022-11-29 |
| CVE-2025-9377 KEV | The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V… | Patch first | 7.2 high | 33.5% | 2025-08-29 |
| CVE-2021-30633 KEV | Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentia… | Patch first | 9.6 critical | 33.2% | 2021-10-08 |
| CVE-2025-21042 KEV | Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. | Patch first | 8.8 high | 33.2% | 2025-09-12 |
| CVE-2025-20393 KEV | A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could a… | Patch first | 10.0 critical | 32.4% | 2025-12-17 |
| CVE-2013-0641 KEV | Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary… | Patch first | 7.8 high | 32.3% | 2013-02-14 |
| CVE-2024-57968 KEV | Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during we… | Patch first | 9.9 critical | 32.3% | 2025-02-03 |
| CVE-2020-8218 KEV | A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution v… | Patch first | 7.2 high | 32.3% | 2020-07-30 |
| CVE-2023-3079 KEV | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… | Patch first | 8.8 high | 32.1% | 2023-06-05 |
| CVE-2017-5070 KEV | Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to ex… | Patch first | 8.8 high | 32.1% | 2017-10-27 |
| CVE-2022-4135 KEV | Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially… | Patch first | 9.6 critical | 31.9% | 2022-11-25 |
| CVE-2026-0300 KEV | A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an una… | Patch first | 9.8 critical | 31.7% | 2026-05-06 |
| CVE-2025-0994 KEV | Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerabili… | Patch first | 8.8 high | 31.3% | 2025-02-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt