CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,733 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
398,733 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-6627 KEV | A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attac… | Patch first | 7.5 high | 6.2% | 2017-09-07 |
| CVE-2019-1069 KEV | An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully e… | Patch first | 7.8 high | 6.1% | 2019-06-12 |
| CVE-2021-27059 KEV | Microsoft Office Remote Code Execution Vulnerability | Patch first | 7.6 high | 6.1% | 2021-03-11 |
| CVE-2021-27101 KEV | Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA… | Patch first | 9.8 critical | 6% | 2021-02-16 |
| CVE-2026-60137 KEV | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which co… | Patch first | 5.9 medium | 5.9% | 2026-07-17 |
| CVE-2022-26500 KEV | Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API f… | Patch first | 8.8 high | 5.8% | 2022-03-17 |
| CVE-2019-6693 KEV | Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup fi… | Patch first | 6.5 medium | 5.8% | 2019-11-21 |
| CVE-2026-42208 KEV | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query… | Patch first | 9.8 critical | 5.8% | 2026-05-08 |
| CVE-2022-3075 KEV | Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to po… | Patch first | 9.6 critical | 5.8% | 2022-09-26 |
| CVE-2023-2136 KEV | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially pe… | Patch first | 9.6 critical | 5.7% | 2023-04-19 |
| CVE-2026-48558 KEV | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When… | Patch first | 10.0 critical | 5.7% | 2026-06-12 |
| CVE-2016-0167 KEV | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2… | Patch first | 7.8 high | 5.7% | 2016-04-12 |
| CVE-2010-3035 KEV | Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to c… | Patch first | 7.5 high | 5.7% | 2010-08-30 |
| CVE-2022-20700 KEV | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… | Patch first | 10.0 critical | 5.7% | 2022-02-10 |
| CVE-2024-30051 KEV | Windows DWM Core Library Elevation of Privilege Vulnerability | Patch first | 7.8 high | 5.6% | 2024-05-14 |
| CVE-2022-32917 KEV | The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7.… | Patch first | 7.8 high | 5.6% | 2022-09-20 |
| CVE-2023-21823 KEV | Windows Graphics Component Remote Code Execution Vulnerability | Patch first | 7.8 high | 5.6% | 2023-02-14 |
| CVE-2022-0492 KEV | A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circums… | Patch first | 7.8 high | 5.5% | 2022-03-03 |
| CVE-2019-15271 KEV | A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker… | Patch first | 8.8 high | 5.5% | 2019-11-26 |
| CVE-2021-27085 KEV | Internet Explorer Remote Code Execution Vulnerability | Patch first | 8.8 high | 5.4% | 2021-03-11 |
| CVE-2020-17087 KEV | Windows Kernel Local Elevation of Privilege Vulnerability | Patch first | 7.8 high | 5.4% | 2020-11-11 |
| CVE-2021-28664 KEV | The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/wr… | Patch first | 8.8 high | 5.4% | 2021-05-10 |
| CVE-2025-10585 KEV | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… | Patch first | 9.8 critical | 5.4% | 2025-09-24 |
| CVE-2017-12319 KEV | A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthen… | Patch first | 5.9 medium | 5.2% | 2018-03-27 |
| CVE-2021-30900 KEV | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.1 and iPadOS 15.… | Patch first | 7.8 high | 5.2% | 2021-08-24 |
| CVE-2015-6175 KEV | The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privi… | Patch first | 7.8 high | 5.1% | 2015-12-09 |
| CVE-2026-25108 KEV | FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted… | Patch first | 8.8 high | 5.1% | 2026-02-13 |
| CVE-2025-13223 KEV | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… | Patch first | 8.8 high | 5% | 2025-11-17 |
| CVE-2021-36741 KEV | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 al… | Patch first | 8.8 high | 5% | 2021-07-29 |
| CVE-2019-16256 KEV | Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location an… | Patch first | 9.8 critical | 4.9% | 2019-09-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt