CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,806 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
185,465 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-62221 KEV | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | Patch first | 7.8 high | 2.5% | 2025-12-09 |
| CVE-2026-7273 KEV | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based… | Patch first | 8.8 high | 2.5% | 2026-06-16 |
| CVE-2025-32975 KEV | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5),… | Patch first | 10.0 critical | 2.5% | 2025-06-24 |
| CVE-2026-21519 KEV | Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | Patch first | 7.8 high | 2.5% | 2026-02-10 |
| CVE-2025-30154 KEV | reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 U… | Patch first | 8.6 high | 2.4% | 2025-03-19 |
| CVE-2022-21919 KEV | Windows User Profile Service Elevation of Privilege Vulnerability | Patch first | 7.0 high | 2.4% | 2022-01-11 |
| CVE-2022-0028 KEV | A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) at… | Patch first | 8.6 high | 2.4% | 2022-08-10 |
| CVE-2018-4344 KEV | A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watc… | Patch first | 7.8 high | 2.4% | 2019-04-03 |
| CVE-2020-0638 KEV | An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker wou… | Patch first | 7.8 high | 2.4% | 2020-01-14 |
| CVE-2022-26486 KEV | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the… | Patch first | 9.6 critical | 2.3% | 2022-12-22 |
| CVE-2025-21391 KEV | Windows Storage Elevation of Privilege Vulnerability | Patch first | 7.1 high | 2.3% | 2025-02-11 |
| CVE-2025-3928 KEV | Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory:… | Patch first | 8.8 high | 2.3% | 2025-04-25 |
| CVE-2025-53521 KEV | When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Softwa… | Patch first | 9.8 critical | 2.3% | 2025-10-15 |
| CVE-2025-32706 KEV | Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | Patch first | 7.8 high | 2.3% | 2025-05-13 |
| CVE-2019-0880 KEV | A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerab… | Patch first | 7.8 high | 2.3% | 2019-07-15 |
| CVE-2020-9818 KEV | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5.… | Patch first | 8.8 high | 2.3% | 2020-06-09 |
| CVE-2022-41073 KEV | Windows Print Spooler Elevation of Privilege Vulnerability | Patch first | 7.8 high | 2.3% | 2022-11-09 |
| CVE-2026-94127 KEV | When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution… | Patch first | 9.8 critical | 2.2% | 2026-09-22 |
| CVE-2021-1782 KEV | A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 20… | Patch first | 7.0 high | 2.2% | 2021-04-02 |
| CVE-2026-11645 KEV | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a… | Patch first | 8.8 high | 2.2% | 2026-06-09 |
| CVE-2026-34621 KEV | Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('… | Patch first | 8.6 high | 2.2% | 2026-04-11 |
| CVE-2025-24993 KEV | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | Patch first | 7.8 high | 2.2% | 2025-03-11 |
| CVE-2025-21043 KEV | Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. | Patch first | 8.8 high | 2.1% | 2025-09-12 |
| CVE-2025-32709 KEV | Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | Patch first | 7.8 high | 2.1% | 2025-05-13 |
| CVE-2026-65660 KEV | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | Patch first | 8.8 high | 2.1% | 2026-08-11 |
| CVE-2026-49869 KEV | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().e… | Patch first | 10.0 critical | 2.1% | 2026-06-26 |
| CVE-2026-45247 KEV | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attacke… | Patch first | 9.8 critical | 2.1% | 2026-05-26 |
| CVE-2023-6448 KEV | Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacke… | Patch first | 9.8 critical | 2.1% | 2023-12-05 |
| CVE-2020-2506 KEV | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers… | Patch first | 7.3 high | 2% | 2021-02-03 |
| CVE-2026-28318 KEV | SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: defla… | Patch first | 7.5 high | 1.9% | 2026-06-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt