CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,882 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
185,484 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2024-29748 KEV | there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pri… | Patch first | 7.8 high | 0.7% | 2024-04-05 |
| CVE-2026-53266 KEV | In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target k… | Patch first | 8.8 high | 0.6% | 2026-06-25 |
| CVE-2021-25487 KEV | Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in ar… | Patch first | 7.3 high | 0.6% | 2021-10-06 |
| CVE-2026-58704 KEV | In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of… | Patch first | 8.8 high | 0.6% | 2026-09-15 |
| CVE-2026-5430 KEV | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to… | Patch first | 10.0 critical | 0.6% | 2026-08-06 |
| CVE-2025-48543 KEV | In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to lo… | Patch first | 8.8 high | 0.5% | 2025-09-04 |
| CVE-2026-42897 KEV | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to p… | Patch first | 8.1 high | 0.5% | 2026-05-14 |
| CVE-2022-48618 KEV | The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker… | Patch first | 7.0 high | 0.5% | 2024-01-09 |
| CVE-2025-21480 KEV | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | Patch first | 8.6 high | 0.5% | 2025-06-03 |
| CVE-2022-22071 KEV | Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapd… | Patch first | 8.4 high | 0.5% | 2022-06-14 |
| CVE-2026-41091 KEV | Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | Patch first | 7.8 high | 0.4% | 2026-05-20 |
| CVE-2026-33825 KEV | Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. | Patch first | 7.8 high | 0.4% | 2026-04-14 |
| CVE-2026-81963 KEV | Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. | Patch first | 7.8 high | 0.4% | 2026-09-08 |
| CVE-2025-43510 KEV | A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26… | Patch first | 7.8 high | 0.4% | 2025-12-12 |
| CVE-2026-56155 KEV | Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally… | Patch first | 7.8 high | 0.3% | 2026-07-14 |
| CVE-2026-68820 KEV | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | Patch first | 7.0 high | 0.3% | 2026-08-11 |
| CVE-2026-3502 KEV | TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update deli… | Patch first | 7.8 high | 0.3% | 2026-03-30 |
| CVE-2025-48572 KEV | In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalati… | Patch first | 7.8 high | 0.3% | 2025-12-08 |
| CVE-2026-87886 KEV | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) befor… | Patch first | 7.8 high | 0.2% | 2026-09-17 |
| CVE-2014-3704 EXP | The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which all… | Patch early | 7.5 high | 100% | 2014-10-16 |
| CVE-2015-7297 EXP | SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different… | Patch early | 7.5 high | 100% | 2015-10-29 |
| CVE-2022-42889 EXP | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolati… | Patch early | 9.8 critical | 99.9% | 2022-10-13 |
| CVE-2019-0232 EXP | When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93… | Patch early | 8.1 high | 99.9% | 2019-04-15 |
| CVE-2020-13379 EXP | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/clien… | Patch early | 8.2 high | 99.9% | 2020-06-03 |
| CVE-2017-12635 EXP | Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.… | Patch early | 9.8 critical | 99.8% | 2017-11-14 |
| CVE-2017-8917 EXP | SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors. | Patch early | 9.8 critical | 99.8% | 2017-05-17 |
| CVE-2020-10220 EXP | An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter. | Patch early | 9.8 critical | 99.7% | 2020-03-07 |
| CVE-2023-27372 EXP | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,… | Patch early | 9.8 critical | 99.7% | 2023-02-28 |
| CVE-2022-37061 EXP | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject an… | Patch early | 9.8 critical | 99.6% | 2022-08-18 |
| CVE-2024-6387 EXP | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals… | Patch early | 8.1 high | 99.5% | 2024-07-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt