CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,648 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
398,648 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-4947 KEV | Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML p… | Patch first | 9.6 critical | 15.2% | 2024-05-15 |
| CVE-2026-34908 KEV | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized cha… | Patch first | 10.0 critical | 15.2% | 2026-05-22 |
| CVE-2015-0310 KEV | Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly re… | Patch first | 7.8 high | 15.1% | 2015-01-23 |
| CVE-2022-38028 KEV | Windows Print Spooler Elevation of Privilege Vulnerability | Patch first | 7.8 high | 14.9% | 2022-10-11 |
| CVE-2022-20708 KEV | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch first | 10.0 critical | 14.9% | 2022-02-10 |
| CVE-2026-56291 KEV | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to… | Patch first | 9.8 critical | 14.9% | 2026-07-09 |
| CVE-2015-2360 KEV | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows… | Patch first | 8.8 high | 14.8% | 2015-06-10 |
| CVE-2021-30883 KEV | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS… | Patch first | 7.8 high | 14.7% | 2021-08-24 |
| CVE-2020-10181 KEV | goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) o… | Patch first | 9.8 critical | 14.7% | 2020-03-11 |
| CVE-2024-8069 KEV | Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user o… | Patch first | 8.0 high | 14.6% | 2024-11-12 |
| CVE-2026-18577 KEV | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 | Patch first | 8.1 high | 14.6% | 2026-08-02 |
| CVE-2019-7193 KEV | This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend… | Patch first | 9.8 critical | 14.4% | 2019-12-05 |
| CVE-2023-28204 KEV | An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and… | Patch first | 6.5 medium | 14.3% | 2023-06-23 |
| CVE-2022-26485 KEV | Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this… | Patch first | 8.8 high | 14.3% | 2022-12-22 |
| CVE-2018-0151 KEV | A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attac… | Patch first | 9.8 critical | 14.2% | 2018-03-28 |
| CVE-2024-49039 KEV | Windows Task Scheduler Elevation of Privilege Vulnerability | Patch first | 8.8 high | 14.2% | 2024-11-12 |
| CVE-2021-22900 KEV | A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to per… | Patch first | 7.2 high | 14.1% | 2021-05-27 |
| CVE-2026-82329 KEV | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to… | Patch first | 9.8 critical | 14.1% | 2026-08-28 |
| CVE-2026-76460 KEV | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vu… | Patch first | 10.0 critical | 14% | 2026-09-16 |
| CVE-2023-38180 KEV | .NET and Visual Studio Denial of Service Vulnerability | Patch first | 7.5 high | 14% | 2023-08-08 |
| CVE-2021-1789 KEV | A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Secur… | Patch first | 8.8 high | 14% | 2021-04-02 |
| CVE-2025-31201 KEV | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visi… | Patch first | 9.8 critical | 14% | 2025-04-16 |
| CVE-2025-29824 KEV | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | Patch first | 7.8 high | 13.9% | 2025-04-08 |
| CVE-2025-42999 KEV | SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialize… | Patch first | 9.1 critical | 13.9% | 2025-05-13 |
| CVE-2019-9875 KEV | Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sendin… | Patch first | 8.8 high | 13.8% | 2019-05-31 |
| CVE-2017-12240 KEV | The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote… | Patch first | 9.8 critical | 13.8% | 2017-09-29 |
| CVE-2022-1364 KEV | Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted… | Patch first | 8.8 high | 13.7% | 2022-07-26 |
| CVE-2024-12686 KEV | A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative… | Patch first | 6.6 medium | 13.7% | 2024-12-18 |
| CVE-2024-38213 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 6.5 medium | 13.6% | 2024-08-13 |
| CVE-2015-4902 KEV | Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deploymen… | Patch first | 5.3 medium | 13.6% | 2015-10-22 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt