CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,648 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
398,648 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-40766 KEV | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource… | Patch first | 9.8 critical | 18.4% | 2024-08-23 |
| CVE-2018-0147 KEV | A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated,… | Patch first | 9.8 critical | 18.2% | 2018-03-08 |
| CVE-2026-87902 KEV | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active the… | Patch first | 8.1 high | 18.2% | 2026-09-22 |
| CVE-2017-0022 KEV | Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1… | Patch first | 6.5 medium | 18.1% | 2017-03-17 |
| CVE-2023-42916 KEV | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 1… | Patch first | 6.5 medium | 17.8% | 2023-11-30 |
| CVE-2010-5326 KEV | The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote atta… | Patch first | 10.0 critical | 17.8% | 2016-05-13 |
| CVE-2026-22719 KEV | VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary comma… | Patch first | 8.1 high | 17.7% | 2026-02-25 |
| CVE-2024-11182 KEV | An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img… | Patch first | 6.1 medium | 17.7% | 2024-11-15 |
| CVE-2022-27926 KEV | A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthe… | Patch first | 6.1 medium | 17.6% | 2022-04-21 |
| CVE-2021-44207 KEV | Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials. | Patch first | 8.1 high | 17.6% | 2021-12-21 |
| CVE-2026-55040 KEV | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. | Patch first | 9.1 critical | 17.5% | 2026-07-14 |
| CVE-2024-38813 KEV | The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerabili… | Patch first | 7.5 high | 17.4% | 2024-09-17 |
| CVE-2020-4006 KEV | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. | Patch first | 9.1 critical | 17.3% | 2020-11-23 |
| CVE-2023-26359 KEV | Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerabili… | Patch first | 9.8 critical | 17% | 2023-03-23 |
| CVE-2022-26904 KEV | Windows User Profile Service Elevation of Privilege Vulnerability | Patch first | 7.0 high | 16.9% | 2022-04-15 |
| CVE-2023-36036 KEV | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Patch first | 7.8 high | 16.7% | 2023-11-14 |
| CVE-2021-30533 KEV | Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via… | Patch first | 6.5 medium | 16.6% | 2021-06-07 |
| CVE-2023-32409 KEV | The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8,… | Patch first | 8.6 high | 16.5% | 2023-06-23 |
| CVE-2020-27950 KEV | A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020… | Patch first | 5.5 medium | 16.5% | 2020-12-08 |
| CVE-2021-20022 KEV | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote… | Patch first | 7.2 high | 16.5% | 2021-04-09 |
| CVE-2023-6345 KEV | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially pe… | Patch first | 9.6 critical | 16.5% | 2023-11-29 |
| CVE-2022-22620 KEV | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safa… | Patch first | 8.8 high | 16.3% | 2022-03-18 |
| CVE-2022-4262 KEV | Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.… | Patch first | 8.8 high | 16% | 2022-12-02 |
| CVE-2020-0986 KEV | An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr… | Patch first | 7.8 high | 15.9% | 2020-06-09 |
| CVE-2026-58644 KEV | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | Patch first | 9.8 critical | 15.9% | 2026-07-14 |
| CVE-2024-20481 KEV | A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)… | Patch first | 5.8 medium | 15.8% | 2024-10-23 |
| CVE-2026-21513 KEV | Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. | Patch first | 8.8 high | 15.6% | 2026-02-10 |
| CVE-2023-50224 KEV | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to di… | Patch first | 6.5 medium | 15.6% | 2024-05-03 |
| CVE-2023-35311 KEV | Microsoft Outlook Security Feature Bypass Vulnerability | Patch first | 8.8 high | 15.5% | 2023-07-11 |
| CVE-2026-34197 KEV | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache… | Patch first | 8.8 high | 15.5% | 2026-04-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt