CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,587 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
398,587 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-6737 KEV | A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely ex… | Patch first | 8.8 high | 45.2% | 2017-07-17 |
| CVE-2024-29988 KEV | SmartScreen Prompt Security Feature Bypass Vulnerability | Patch first | 8.8 high | 44.9% | 2024-04-09 |
| CVE-2015-2425 KEV | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… | Patch first | 8.8 high | 44.7% | 2015-07-14 |
| CVE-2013-3900 KEV | Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and… | Patch first | 5.5 medium | 44.6% | 2013-12-11 |
| CVE-2020-15999 KEV | Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafte… | Patch first | 9.6 critical | 44.3% | 2020-11-03 |
| CVE-2024-9379 KEV | SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrar… | Patch first | 6.5 medium | 43.8% | 2024-10-08 |
| CVE-2014-100005 KEV | Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to h… | Patch first | 8.0 high | 43.5% | 2015-01-13 |
| CVE-2023-36874 KEV | Windows Error Reporting Service Elevation of Privilege Vulnerability | Patch first | 7.8 high | 43.4% | 2023-07-11 |
| CVE-2007-0671 KEV | Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attacke… | Patch first | 8.8 high | 43.2% | 2007-02-03 |
| CVE-2009-0238 KEV | Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, a… | Patch first | 8.8 high | 43.2% | 2009-02-25 |
| CVE-2021-42292 KEV | Microsoft Excel Security Feature Bypass Vulnerability | Patch first | 7.8 high | 43% | 2021-11-10 |
| CVE-2025-2775 KEV | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionalit… | Patch first | 9.3 critical | 43% | 2025-05-07 |
| CVE-2023-49105 KEV | An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the use… | Patch first | 9.8 critical | 42.9% | 2023-11-21 |
| CVE-2026-20131 KEV | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote… | Patch first | 10.0 critical | 42.7% | 2026-03-04 |
| CVE-2020-0787 KEV | An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka… | Patch first | 7.8 high | 42.5% | 2020-03-12 |
| CVE-2020-12271 KEV | A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April… | Patch first | 9.8 critical | 42.4% | 2020-04-27 |
| CVE-2026-48282 KEV | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vuln… | Patch first | 10.0 critical | 42.4% | 2026-06-30 |
| CVE-2024-41710 KEV | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136… | Patch first | 7.2 high | 41.6% | 2024-08-12 |
| CVE-2019-16928 KEV | Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_… | Patch first | 9.8 critical | 41.6% | 2019-09-27 |
| CVE-2023-33538 KEV | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/… | Patch first | 8.8 high | 41.6% | 2023-06-07 |
| CVE-2024-38178 KEV | Scripting Engine Memory Corruption Vulnerability | Patch first | 7.5 high | 41.4% | 2024-08-13 |
| CVE-2023-4762 KEV | Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium s… | Patch first | 8.8 high | 41.4% | 2023-09-05 |
| CVE-2011-1823 KEV | The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local user… | Patch first | 7.8 high | 41.4% | 2011-06-09 |
| CVE-2021-22894 KEV | A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the… | Patch first | 8.8 high | 41.3% | 2021-05-27 |
| CVE-2022-21999 KEV | Windows Print Spooler Elevation of Privilege Vulnerability | Patch first | 7.8 high | 41% | 2022-02-09 |
| CVE-2023-21674 KEV | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Patch first | 8.8 high | 41% | 2023-01-10 |
| CVE-2023-2033 KEV | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… | Patch first | 8.8 high | 40.8% | 2023-04-14 |
| CVE-2017-5030 KEV | Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a… | Patch first | 8.8 high | 40.6% | 2017-04-24 |
| CVE-2015-2424 KEV | Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow… | Patch first | 8.8 high | 40.4% | 2015-07-14 |
| CVE-2015-0666 KEV | Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to r… | Patch first | 7.5 high | 40.4% | 2015-04-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt