CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,436 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-26
168,978 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-37976 KEV | Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information fr… | Patch first | 6.5 medium | 19.9% | 2021-10-08 |
| CVE-2023-36761 KEV | Microsoft Word Information Disclosure Vulnerability | Patch first | 6.5 medium | 19.6% | 2023-09-12 |
| CVE-2021-41379 KEV | Windows Installer Elevation of Privilege Vulnerability | Patch first | 5.5 medium | 19.5% | 2021-11-10 |
| CVE-2024-20359 KEV | A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Secur… | Patch first | 6.0 medium | 19.4% | 2024-04-24 |
| CVE-2014-2120 KEV | Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to injec… | Patch first | 6.1 medium | 18.8% | 2014-03-19 |
| CVE-2020-11899 KEV | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. | Patch first | 5.4 medium | 18.6% | 2020-06-17 |
| CVE-2019-5591 KEV | A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impers… | Patch first | 6.5 medium | 18.4% | 2020-08-14 |
| CVE-2017-0022 KEV | Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1… | Patch first | 6.5 medium | 18.1% | 2017-03-17 |
| CVE-2023-42916 KEV | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 1… | Patch first | 6.5 medium | 17.8% | 2023-11-30 |
| CVE-2024-11182 KEV | An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img… | Patch first | 6.1 medium | 17.7% | 2024-11-15 |
| CVE-2022-27926 KEV | A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthe… | Patch first | 6.1 medium | 17.6% | 2022-04-21 |
| CVE-2021-30533 KEV | Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via… | Patch first | 6.5 medium | 16.6% | 2021-06-07 |
| CVE-2020-27950 KEV | A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020… | Patch first | 5.5 medium | 16.5% | 2020-12-08 |
| CVE-2024-20481 KEV | A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)… | Patch first | 5.8 medium | 15.8% | 2024-10-23 |
| CVE-2023-50224 KEV | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to di… | Patch first | 6.5 medium | 15.6% | 2024-05-03 |
| CVE-2023-28204 KEV | An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and… | Patch first | 6.5 medium | 14.3% | 2023-06-23 |
| CVE-2024-12686 KEV | A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative… | Patch first | 6.6 medium | 13.7% | 2024-12-18 |
| CVE-2024-38213 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 6.5 medium | 13.6% | 2024-08-13 |
| CVE-2015-4902 KEV | Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deploymen… | Patch first | 5.3 medium | 13.6% | 2015-10-22 |
| CVE-2023-41991 KEV | A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypa… | Patch first | 5.5 medium | 13.4% | 2023-09-21 |
| CVE-2022-22948 KEV | The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative acc… | Patch first | 6.5 medium | 13.3% | 2022-03-29 |
| CVE-2022-20821 KEV | A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is… | Patch first | 6.5 medium | 11.5% | 2022-05-26 |
| CVE-2025-48927 KEV | The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the… | Patch first | 5.3 medium | 11.1% | 2025-05-28 |
| CVE-2022-41328 KEV | A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.… | Patch first | 6.7 medium | 10.7% | 2023-03-07 |
| CVE-2022-41223 KEV | The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attac… | Patch first | 6.8 medium | 10.7% | 2022-11-22 |
| CVE-2022-40765 KEV | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal… | Patch first | 6.8 medium | 10.6% | 2022-11-22 |
| CVE-2022-2586 KEV | It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was… | Patch first | 5.3 medium | 10.2% | 2024-01-08 |
| CVE-2024-38217 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 10% | 2024-09-10 |
| CVE-2019-0703 KEV | An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosur… | Patch first | 6.5 medium | 9.6% | 2019-04-09 |
| CVE-2019-0676 KEV | An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this… | Patch first | 6.5 medium | 8.1% | 2019-03-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt