CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,692 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
398,692 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2021-28310 KEV | Win32k Elevation of Privilege Vulnerability | Patch first | 7.8 high | 8.3% | 2021-04-13 |
| CVE-2024-38189 KEV | Microsoft Project Remote Code Execution Vulnerability | Patch first | 8.8 high | 8.2% | 2024-08-13 |
| CVE-2019-0676 KEV | An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this… | Patch first | 6.5 medium | 8.1% | 2019-03-05 |
| CVE-2019-11634 KEV | Citrix Workspace App before 1904 for Windows has Incorrect Access Control. | Patch first | 9.8 critical | 8% | 2019-05-22 |
| CVE-2021-38646 KEV | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | Patch first | 7.8 high | 8% | 2021-09-15 |
| CVE-2022-3723 KEV | Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.… | Patch first | 8.8 high | 7.9% | 2022-11-01 |
| CVE-2023-28434 KEV | Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket… | Patch first | 8.8 high | 7.9% | 2023-03-22 |
| CVE-2026-18556 KEV | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central… | Patch first | 7.4 high | 7.9% | 2026-08-01 |
| CVE-2023-0386 KEV | A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s… | Patch first | 7.8 high | 7.9% | 2023-03-22 |
| CVE-2021-4102 KEV | Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Patch first | 8.8 high | 7.8% | 2022-02-11 |
| CVE-2018-19323 KEV | The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GUR… | Patch first | 9.8 critical | 7.8% | 2018-12-21 |
| CVE-2012-1710 KEV | Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect c… | Patch first | 9.8 critical | 7.8% | 2012-05-03 |
| CVE-2025-5419 KEV | Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a craf… | Patch first | 8.8 high | 7.8% | 2025-06-03 |
| CVE-2018-0172 KEV | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remo… | Patch first | 8.6 high | 7.8% | 2018-03-28 |
| CVE-2012-2034 KEV | Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux;… | Patch first | 7.5 high | 7.8% | 2012-06-09 |
| CVE-2018-0155 KEV | A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-… | Patch first | 8.6 high | 7.7% | 2018-03-28 |
| CVE-2021-1870 KEV | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update… | Patch first | 9.8 critical | 7.7% | 2021-04-02 |
| CVE-2018-0173 KEV | A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv… | Patch first | 8.6 high | 7.6% | 2018-03-28 |
| CVE-2018-0174 KEV | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remo… | Patch first | 8.6 high | 7.6% | 2018-03-28 |
| CVE-2024-5274 KEV | Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML… | Patch first | 9.6 critical | 7.5% | 2024-05-28 |
| CVE-2020-1040 KEV | A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user o… | Patch first | 9.0 critical | 7.4% | 2020-07-14 |
| CVE-2021-30554 KEV | Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa… | Patch first | 8.8 high | 7.4% | 2021-07-02 |
| CVE-2017-6744 KEV | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authent… | Patch first | 8.8 high | 7.3% | 2017-07-17 |
| CVE-2025-24472 KEV | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 throug… | Patch first | 8.1 high | 7.2% | 2025-02-11 |
| CVE-2026-20805 KEV | Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. | Patch first | 5.5 medium | 7.2% | 2026-01-13 |
| CVE-2018-0158 KEV | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,… | Patch first | 8.6 high | 7.2% | 2018-03-28 |
| CVE-2024-38080 KEV | Windows Hyper-V Elevation of Privilege Vulnerability | Patch first | 7.8 high | 7.1% | 2024-07-09 |
| CVE-2021-1879 KEV | This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. P… | Patch first | 6.1 medium | 7.1% | 2021-04-02 |
| CVE-2019-0344 KEV | Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to exe… | Patch first | 9.8 critical | 7.1% | 2019-08-14 |
| CVE-2022-24521 KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Patch first | 7.8 high | 7.1% | 2022-04-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt