CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,692 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
185,417 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-20128 KEV | A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DC… | Patch first | 7.5 high | 7.1% | 2026-02-25 |
| CVE-2020-6820 KEV | Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild ab… | Patch first | 8.1 high | 7.1% | 2020-04-24 |
| CVE-2021-30713 KEV | A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass P… | Patch first | 7.8 high | 7% | 2021-09-08 |
| CVE-2026-19490 KEV | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1… | Patch first | 9.8 critical | 7% | 2026-08-19 |
| CVE-2021-1871 KEV | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update… | Patch first | 9.8 critical | 7% | 2021-04-02 |
| CVE-2021-30952 KEV | An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPa… | Patch first | 7.8 high | 7% | 2021-08-24 |
| CVE-2019-1064 KEV | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfu… | Patch first | 7.8 high | 6.9% | 2019-06-12 |
| CVE-2018-0159 KEV | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could a… | Patch first | 7.5 high | 6.9% | 2018-03-28 |
| CVE-2026-15409 KEV | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacke… | Patch first | 10.0 critical | 6.8% | 2026-07-14 |
| CVE-2023-26369 KEV | Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write v… | Patch first | 7.8 high | 6.7% | 2023-09-13 |
| CVE-2022-27518 KEV | Unauthenticated remote arbitrary code execution | Patch first | 9.8 critical | 6.7% | 2022-12-13 |
| CVE-2023-7024 KEV | Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted… | Patch first | 8.8 high | 6.7% | 2023-12-21 |
| CVE-2026-34486 KEV | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.… | Patch first | 7.5 high | 6.6% | 2026-04-09 |
| CVE-2021-33739 KEV | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Patch first | 8.4 high | 6.6% | 2021-06-08 |
| CVE-2025-24990 KEV | Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an… | Patch first | 7.8 high | 6.4% | 2025-10-14 |
| CVE-2020-16010 KEV | Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to po… | Patch first | 9.6 critical | 6.4% | 2020-11-03 |
| CVE-2024-38106 KEV | Windows Kernel Elevation of Privilege Vulnerability | Patch first | 7.0 high | 6.3% | 2024-08-13 |
| CVE-2026-50751 KEV | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote atta… | Patch first | 9.3 critical | 6.3% | 2026-06-08 |
| CVE-2024-38014 KEV | Windows Installer Elevation of Privilege Vulnerability | Patch first | 7.8 high | 6.3% | 2024-09-10 |
| CVE-2020-8468 KEV | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulner… | Patch first | 8.8 high | 6.2% | 2020-03-18 |
| CVE-2017-6627 KEV | A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attac… | Patch first | 7.5 high | 6.2% | 2017-09-07 |
| CVE-2019-1069 KEV | An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully e… | Patch first | 7.8 high | 6.1% | 2019-06-12 |
| CVE-2021-27059 KEV | Microsoft Office Remote Code Execution Vulnerability | Patch first | 7.6 high | 6.1% | 2021-03-11 |
| CVE-2021-27101 KEV | Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA… | Patch first | 9.8 critical | 6% | 2021-02-16 |
| CVE-2022-26500 KEV | Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API f… | Patch first | 8.8 high | 5.8% | 2022-03-17 |
| CVE-2026-42208 KEV | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query… | Patch first | 9.8 critical | 5.8% | 2026-05-08 |
| CVE-2022-3075 KEV | Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to po… | Patch first | 9.6 critical | 5.8% | 2022-09-26 |
| CVE-2023-2136 KEV | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially pe… | Patch first | 9.6 critical | 5.7% | 2023-04-19 |
| CVE-2026-48558 KEV | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When… | Patch first | 10.0 critical | 5.7% | 2026-06-12 |
| CVE-2016-0167 KEV | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2… | Patch first | 7.8 high | 5.7% | 2016-04-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt