CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,612 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
185,399 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-4171 KEV | Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as explo… | Patch first | 9.8 critical | 20.1% | 2016-06-16 |
| CVE-2021-21148 KEV | Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML… | Patch first | 8.8 high | 20% | 2021-02-09 |
| CVE-2026-93616 KEV | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Manageme… | Patch first | 9.8 critical | 19.7% | 2026-09-22 |
| CVE-2025-7775 KEV | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is confi… | Patch first | 9.8 critical | 19.6% | 2025-08-26 |
| CVE-2025-66376 KEV | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives… | Patch first | 7.2 high | 19.6% | 2026-01-05 |
| CVE-2022-26871 KEV | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which co… | Patch first | 9.8 critical | 19.5% | 2022-03-29 |
| CVE-2016-1010 KEV | Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux,… | Patch first | 8.8 high | 19.3% | 2016-03-12 |
| CVE-2025-67038 KEV | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. T… | Patch first | 9.8 critical | 19.3% | 2026-03-11 |
| CVE-2016-7836 KEV | SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the manag… | Patch first | 9.8 critical | 19.2% | 2017-06-09 |
| CVE-2023-7101 KEV | Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code executi… | Patch first | 7.8 high | 19.1% | 2023-12-24 |
| CVE-2026-72898 KEV | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access t… | Patch first | 10.0 critical | 19% | 2026-08-10 |
| CVE-2026-9586 KEV | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning… | Patch first | 9.8 critical | 19% | 2026-07-17 |
| CVE-2023-37450 KEV | The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9… | Patch first | 8.8 high | 19% | 2023-07-27 |
| CVE-2015-5123 KEV | Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windo… | Patch first | 9.8 critical | 18.8% | 2015-07-14 |
| CVE-2016-7892 KEV | Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class.… | Patch first | 8.8 high | 18.8% | 2016-12-15 |
| CVE-2022-22047 KEV | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | Patch first | 7.8 high | 18.8% | 2022-07-12 |
| CVE-2025-31200 KEV | A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS… | Patch first | 9.8 critical | 18.8% | 2025-04-16 |
| CVE-2024-7965 KEV | Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a craf… | Patch first | 8.8 high | 18.5% | 2024-08-21 |
| CVE-2022-22718 KEV | Windows Print Spooler Elevation of Privilege Vulnerability | Patch first | 7.8 high | 18.5% | 2022-02-09 |
| CVE-2018-8440 KEV | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevat… | Patch first | 7.8 high | 18.4% | 2018-09-13 |
| CVE-2024-40766 KEV | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource… | Patch first | 9.8 critical | 18.4% | 2024-08-23 |
| CVE-2018-0147 KEV | A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated,… | Patch first | 9.8 critical | 18.2% | 2018-03-08 |
| CVE-2026-87902 KEV | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active the… | Patch first | 8.1 high | 18.2% | 2026-09-22 |
| CVE-2010-5326 KEV | The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote atta… | Patch first | 10.0 critical | 17.8% | 2016-05-13 |
| CVE-2026-22719 KEV | VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary comma… | Patch first | 8.1 high | 17.7% | 2026-02-25 |
| CVE-2021-44207 KEV | Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials. | Patch first | 8.1 high | 17.6% | 2021-12-21 |
| CVE-2026-55040 KEV | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. | Patch first | 9.1 critical | 17.5% | 2026-07-14 |
| CVE-2024-38813 KEV | The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerabili… | Patch first | 7.5 high | 17.4% | 2024-09-17 |
| CVE-2020-4006 KEV | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. | Patch first | 9.1 critical | 17.3% | 2020-11-23 |
| CVE-2023-26359 KEV | Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerabili… | Patch first | 9.8 critical | 17% | 2023-03-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt