CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,882 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
185,484 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-3910 KEV | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a… | Patch first | 8.8 high | 1% | 2026-03-13 |
| CVE-2021-23874 KEV | Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execut… | Patch first | 8.2 high | 1% | 2021-02-10 |
| CVE-2025-22225 KEV | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write… | Patch first | 8.2 high | 1% | 2025-03-04 |
| CVE-2025-27038 KEV | Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. | Patch first | 7.5 high | 1% | 2025-06-03 |
| CVE-2026-8452 KEV | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the applianc… | Patch first | 9.8 critical | 1% | 2026-06-30 |
| CVE-2026-48172 KEV | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best… | Patch first | 9.8 critical | 1% | 2026-05-21 |
| CVE-2026-20349 KEV | A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Th… | Patch first | 8.6 high | 1% | 2026-08-11 |
| CVE-2026-16812 KEV | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and… | Patch first | 10.0 critical | 1% | 2026-07-27 |
| CVE-2021-1048 KEV | In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privil… | Patch first | 7.8 high | 1% | 2021-12-15 |
| CVE-2025-39964 KEV | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes… | Patch first | 7.8 high | 1% | 2025-10-13 |
| CVE-2026-8398 KEV | A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distribu… | Patch first | 9.8 critical | 1% | 2026-05-15 |
| CVE-2023-42824 KEV | The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privi… | Patch first | 7.8 high | 0.9% | 2023-10-04 |
| CVE-2026-84869 KEV | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host… | Patch first | 9.9 critical | 0.9% | 2026-09-08 |
| CVE-2023-33106 KEV | Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. | Patch first | 8.4 high | 0.9% | 2023-12-05 |
| CVE-2023-33107 KEV | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. | Patch first | 8.4 high | 0.9% | 2023-12-05 |
| CVE-2026-55255 KEV | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerabilit… | Patch first | 8.4 high | 0.9% | 2026-06-23 |
| CVE-2025-21479 KEV | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | Patch first | 8.6 high | 0.8% | 2025-06-03 |
| CVE-2026-59822 KEV | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed… | Patch first | 8.2 high | 0.8% | 2026-07-08 |
| CVE-2020-9859 KEV | A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Su… | Patch first | 7.8 high | 0.8% | 2020-06-05 |
| CVE-2026-46817 KEV | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2… | Patch first | 9.8 critical | 0.8% | 2026-05-28 |
| CVE-2026-54420 KEV | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web sh… | Patch first | 8.5 high | 0.8% | 2026-06-14 |
| CVE-2024-4610 KEV | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improp… | Patch first | 7.8 high | 0.8% | 2024-06-07 |
| CVE-2024-43093 KEV | In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive direct… | Patch first | 7.3 high | 0.7% | 2024-11-13 |
| CVE-2026-53362 KEV | In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), w… | Patch first | 7.8 high | 0.7% | 2026-07-04 |
| CVE-2026-3909 KEV | Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTM… | Patch first | 8.8 high | 0.7% | 2026-03-13 |
| CVE-2026-5281 KEV | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrar… | Patch first | 8.8 high | 0.7% | 2026-04-01 |
| CVE-2019-8526 KEV | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain… | Patch first | 7.8 high | 0.7% | 2019-12-18 |
| CVE-2023-33063 KEV | Memory corruption in DSP Services during a remote call from HLOS to DSP. | Patch first | 7.8 high | 0.7% | 2023-12-05 |
| CVE-2021-39793 KEV | In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local… | Patch first | 7.8 high | 0.7% | 2022-03-16 |
| CVE-2024-43047 KEV | Memory corruption while maintaining memory maps of HLOS memory. | Patch first | 7.8 high | 0.7% | 2024-10-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt