CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,648 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
185,406 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-38180 KEV | .NET and Visual Studio Denial of Service Vulnerability | Patch first | 7.5 high | 14% | 2023-08-08 |
| CVE-2021-1789 KEV | A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Secur… | Patch first | 8.8 high | 14% | 2021-04-02 |
| CVE-2025-31201 KEV | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visi… | Patch first | 9.8 critical | 14% | 2025-04-16 |
| CVE-2025-29824 KEV | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | Patch first | 7.8 high | 13.9% | 2025-04-08 |
| CVE-2025-42999 KEV | SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialize… | Patch first | 9.1 critical | 13.9% | 2025-05-13 |
| CVE-2019-9875 KEV | Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sendin… | Patch first | 8.8 high | 13.8% | 2019-05-31 |
| CVE-2017-12240 KEV | The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote… | Patch first | 9.8 critical | 13.8% | 2017-09-29 |
| CVE-2022-1364 KEV | Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted… | Patch first | 8.8 high | 13.7% | 2022-07-26 |
| CVE-2022-38181 KEV | The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p… | Patch first | 8.8 high | 13.6% | 2022-10-25 |
| CVE-2021-27876 KEV | An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which… | Patch first | 8.1 high | 13.5% | 2021-03-01 |
| CVE-2021-30858 KEV | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing… | Patch first | 8.8 high | 13.4% | 2021-08-24 |
| CVE-2026-22769 KEV | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an… | Patch first | 10.0 critical | 13.3% | 2026-02-17 |
| CVE-2026-86218 KEV | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. | Patch first | 9.8 critical | 12.9% | 2026-09-06 |
| CVE-2026-42271 KEV | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used… | Patch first | 8.8 high | 12.8% | 2026-05-08 |
| CVE-2025-6554 KEV | Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chrom… | Patch first | 8.1 high | 12.6% | 2025-06-30 |
| CVE-2024-21410 KEV | Microsoft Exchange Server Elevation of Privilege Vulnerability | Patch first | 9.8 critical | 12.6% | 2024-02-13 |
| CVE-2022-22675 KEV | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS M… | Patch first | 7.8 high | 12.5% | 2022-05-26 |
| CVE-2022-20775 KEV | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is… | Patch first | 7.8 high | 12.5% | 2022-09-30 |
| CVE-2023-36424 KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Patch first | 7.8 high | 12.2% | 2023-11-14 |
| CVE-2023-32373 KEV | A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 an… | Patch first | 8.8 high | 12.2% | 2023-06-23 |
| CVE-2021-28663 KEV | The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-af… | Patch first | 8.8 high | 12.1% | 2021-05-10 |
| CVE-2023-21715 KEV | Microsoft Publisher Security Feature Bypass Vulnerability | Patch first | 7.3 high | 12% | 2023-02-14 |
| CVE-2023-36033 KEV | Windows DWM Core Library Elevation of Privilege Vulnerability | Patch first | 7.8 high | 12% | 2023-11-14 |
| CVE-2017-11292 KEV | Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the… | Patch first | 8.8 high | 11.9% | 2017-10-22 |
| CVE-2020-8599 KEV | Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an ar… | Patch first | 9.8 critical | 11.9% | 2020-03-18 |
| CVE-2026-15410 KEV | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Co… | Patch first | 7.2 high | 11.8% | 2026-07-14 |
| CVE-2026-73570 KEV | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP… | Patch first | 8.9 high | 11.7% | 2026-08-13 |
| CVE-2021-37973 KEV | Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially per… | Patch first | 9.6 critical | 11.7% | 2021-10-08 |
| CVE-2020-3118 KEV | A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute… | Patch first | 8.8 high | 11.7% | 2020-02-05 |
| CVE-2022-22587 KEV | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS M… | Patch first | 9.8 critical | 11.6% | 2022-03-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt