CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,692 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
398,692 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-3433 KEV | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, l… | Patch first | 7.8 high | 10% | 2020-08-17 |
| CVE-2024-38217 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 10% | 2024-09-10 |
| CVE-2022-32893 KEV | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1,… | Patch first | 8.8 high | 9.9% | 2022-08-24 |
| CVE-2021-21193 KEV | Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… | Patch first | 8.8 high | 9.9% | 2021-03-16 |
| CVE-2026-64849 KEV | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated… | Patch first | 9.3 critical | 9.8% | 2026-08-17 |
| CVE-2026-42018 KEV | JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing s… | Patch first | 7.5 high | 9.8% | 2026-08-12 |
| CVE-2026-63077 KEV | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | Patch first | 9.8 critical | 9.8% | 2026-07-27 |
| CVE-2022-20701 KEV | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch first | 10.0 critical | 9.7% | 2022-02-10 |
| CVE-2019-0703 KEV | An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosur… | Patch first | 6.5 medium | 9.6% | 2019-04-09 |
| CVE-2025-6558 KEV | Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform… | Patch first | 8.8 high | 9.6% | 2025-07-15 |
| CVE-2023-41992 KEV | The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attack… | Patch first | 7.8 high | 9.5% | 2023-09-21 |
| CVE-2023-23529 KEV | A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ve… | Patch first | 8.8 high | 9.5% | 2023-02-27 |
| CVE-2026-35273 KEV | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions th… | Patch first | 9.8 critical | 9.4% | 2026-06-11 |
| CVE-2021-21206 KEV | Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa… | Patch first | 8.8 high | 9.3% | 2021-04-26 |
| CVE-2023-42917 KEV | A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safar… | Patch first | 8.8 high | 9.3% | 2023-11-30 |
| CVE-2021-34486 KEV | Windows Event Tracing Elevation of Privilege Vulnerability | Patch first | 7.8 high | 9.3% | 2021-08-12 |
| CVE-2022-20703 KEV | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch first | 10.0 critical | 9.2% | 2022-02-10 |
| CVE-2026-35616 KEV | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized c… | Patch first | 9.8 critical | 9.1% | 2026-04-04 |
| CVE-2022-23748 KEV | mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what condi… | Patch first | 7.8 high | 9.1% | 2022-11-17 |
| CVE-2021-30563 KEV | Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Patch first | 8.8 high | 8.9% | 2021-08-03 |
| CVE-2022-0995 KEV | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of th… | Patch first | 7.8 high | 8.8% | 2022-03-25 |
| CVE-2025-43529 KEV | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and i… | Patch first | 8.8 high | 8.8% | 2025-12-17 |
| CVE-2026-83548 KEV | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unau… | Patch first | 10.0 critical | 8.8% | 2026-09-01 |
| CVE-2018-14558 KEV | An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9),… | Patch first | 9.8 critical | 8.7% | 2018-10-30 |
| CVE-2026-42016 KEV | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signat… | Patch first | 8.1 high | 8.6% | 2026-07-27 |
| CVE-2018-0156 KEV | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigge… | Patch first | 7.5 high | 8.6% | 2018-03-28 |
| CVE-2019-1388 KEV | An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certi… | Patch first | 7.8 high | 8.6% | 2019-11-12 |
| CVE-2022-42856 KEV | A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and i… | Patch first | 8.8 high | 8.5% | 2022-12-15 |
| CVE-2025-41244 KEV | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges… | Patch first | 7.8 high | 8.4% | 2025-09-29 |
| CVE-2024-4671 KEV | Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially p… | Patch first | 9.6 critical | 8.3% | 2024-05-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt