CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,672 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
185,406 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-38648 KEV | Open Management Infrastructure Elevation of Privilege Vulnerability | Patch first | 7.8 high | 11.4% | 2021-09-15 |
| CVE-2021-27103 KEV | Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later. | Patch first | 9.8 critical | 11.4% | 2021-02-16 |
| CVE-2017-6740 KEV | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authent… | Patch first | 8.8 high | 11.1% | 2017-07-17 |
| CVE-2013-0648 KEV | Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on… | Patch first | 8.8 high | 11.1% | 2013-02-27 |
| CVE-2017-0005 KEV | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 201… | Patch first | 7.8 high | 11% | 2017-03-17 |
| CVE-2024-4761 KEV | Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HT… | Patch first | 8.8 high | 11% | 2024-05-14 |
| CVE-2021-30762 KEV | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content ma… | Patch first | 8.8 high | 11% | 2021-09-08 |
| CVE-2020-8467 KEV | A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arb… | Patch first | 8.8 high | 10.9% | 2020-03-18 |
| CVE-2017-6743 KEV | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authent… | Patch first | 8.8 high | 10.9% | 2017-07-17 |
| CVE-2017-6739 KEV | A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely ex… | Patch first | 8.8 high | 10.9% | 2017-07-17 |
| CVE-2017-6738 KEV | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authent… | Patch first | 8.8 high | 10.9% | 2017-07-17 |
| CVE-2023-23376 KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Patch first | 7.8 high | 10.9% | 2023-02-14 |
| CVE-2022-23176 KEV | WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session… | Patch first | 8.8 high | 10.8% | 2022-02-24 |
| CVE-2026-83549 KEV | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in th… | Patch first | 7.8 high | 10.8% | 2026-09-01 |
| CVE-2022-26925 KEV | Windows LSA Spoofing Vulnerability | Patch first | 8.1 high | 10.7% | 2022-05-10 |
| CVE-2020-15069 KEV | Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access.… | Patch first | 9.8 critical | 10.7% | 2020-06-29 |
| CVE-2024-23222 KEV | A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.… | Patch first | 8.8 high | 10.6% | 2024-01-23 |
| CVE-2020-6572 KEV | Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page. | Patch first | 8.8 high | 10.6% | 2021-01-14 |
| CVE-2025-6543 KEV | Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gatew… | Patch first | 9.8 critical | 10.6% | 2025-06-25 |
| CVE-2021-30761 KEV | A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content… | Patch first | 8.8 high | 10.5% | 2021-09-08 |
| CVE-2013-0643 KEV | The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x bef… | Patch first | 8.8 high | 10.5% | 2013-02-27 |
| CVE-2020-27932 KEV | A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9… | Patch first | 7.8 high | 10.3% | 2020-12-08 |
| CVE-2021-43890 KEV | We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt… | Patch first | 7.1 high | 10.3% | 2021-12-15 |
| CVE-2021-33771 KEV | Windows Kernel Elevation of Privilege Vulnerability | Patch first | 7.8 high | 10.2% | 2021-07-14 |
| CVE-2026-63030 KEV | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__no… | Patch first | 9.8 critical | 10.1% | 2026-07-17 |
| CVE-2015-2546 KEV | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012… | Patch first | 8.2 high | 10.1% | 2015-09-09 |
| CVE-2024-44308 KEV | The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS… | Patch first | 8.8 high | 10.1% | 2024-11-20 |
| CVE-2024-6047 KEV | Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vul… | Patch first | 9.8 critical | 10.1% | 2024-06-17 |
| CVE-2020-3433 KEV | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, l… | Patch first | 7.8 high | 10% | 2020-08-17 |
| CVE-2023-32046 KEV | Windows MSHTML Platform Elevation of Privilege Vulnerability | Patch first | 7.8 high | 10% | 2023-07-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt