CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,759 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
185,465 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-87491 KEV | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted… | Patch first | 8.8 high | 3.1% | 2026-09-09 |
| CVE-2017-0001 KEV | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 201… | Patch first | 7.8 high | 3.1% | 2017-03-17 |
| CVE-2021-43226 KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Patch first | 7.8 high | 3.1% | 2021-12-15 |
| CVE-2022-41125 KEV | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | Patch first | 7.8 high | 3% | 2022-11-09 |
| CVE-2026-50522 KEV | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | Patch first | 9.8 critical | 3% | 2026-07-14 |
| CVE-2020-6819 KEV | Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the… | Patch first | 8.1 high | 3% | 2020-04-24 |
| CVE-2018-8589 KEV | An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnera… | Patch first | 7.8 high | 3% | 2018-11-14 |
| CVE-2021-30666 KEV | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may… | Patch first | 8.8 high | 3% | 2021-09-08 |
| CVE-2021-29256 KEV | . The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege es… | Patch first | 8.8 high | 3% | 2021-05-24 |
| CVE-2024-32896 KEV | there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pri… | Patch first | 7.8 high | 3% | 2024-06-13 |
| CVE-2024-7262 KEV | Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows all… | Patch first | 7.8 high | 2.9% | 2024-08-15 |
| CVE-2024-11667 KEV | A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmwar… | Patch first | 7.5 high | 2.9% | 2024-11-27 |
| CVE-2021-30983 KEV | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to ex… | Patch first | 7.8 high | 2.9% | 2021-08-24 |
| CVE-2021-38649 KEV | Open Management Infrastructure Elevation of Privilege Vulnerability | Patch first | 7.0 high | 2.9% | 2021-09-15 |
| CVE-2025-39682 KEV | In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must… | Patch first | 9.8 critical | 2.9% | 2025-09-05 |
| CVE-2025-61932 KEV | Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing a… | Patch first | 9.8 critical | 2.8% | 2025-10-20 |
| CVE-2020-16013 KEV | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a craf… | Patch first | 8.8 high | 2.8% | 2021-01-08 |
| CVE-2020-16017 KEV | Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potenti… | Patch first | 9.6 critical | 2.7% | 2021-01-08 |
| CVE-2021-38645 KEV | Open Management Infrastructure Elevation of Privilege Vulnerability | Patch first | 7.8 high | 2.7% | 2021-09-15 |
| CVE-2022-42948 KEV | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to… | Patch first | 9.8 critical | 2.7% | 2023-03-24 |
| CVE-2026-45659 KEV | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | Patch first | 8.8 high | 2.7% | 2026-05-22 |
| CVE-2024-36971 KEV | In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce p… | Patch first | 7.8 high | 2.7% | 2024-06-10 |
| CVE-2023-29492 KEV | Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not prov… | Patch first | 9.8 critical | 2.7% | 2023-04-11 |
| CVE-2024-38226 KEV | Microsoft Publisher Security Feature Bypass Vulnerability | Patch first | 7.3 high | 2.7% | 2024-09-10 |
| CVE-2020-24557 KEV | A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particula… | Patch first | 7.8 high | 2.7% | 2020-09-01 |
| CVE-2025-59230 KEV | Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | Patch first | 7.8 high | 2.7% | 2025-10-14 |
| CVE-2019-6223 KEV | A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1… | Patch first | 7.5 high | 2.6% | 2019-03-05 |
| CVE-2023-35674 KEV | In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local es… | Patch first | 7.8 high | 2.6% | 2023-09-11 |
| CVE-2026-59310 KEV | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this is… | Patch first | 9.8 critical | 2.6% | 2026-07-30 |
| CVE-2026-6973 KEV | An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative… | Patch first | 7.2 high | 2.5% | 2026-05-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt