CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,882 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
398,882 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2022-41091 KEV | Windows Mark of the Web Security Feature Bypass Vulnerability | Patch first | 5.4 medium | 1.8% | 2022-11-09 |
| CVE-2018-19322 KEV | The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.2… | Patch first | 7.8 high | 1.8% | 2018-12-21 |
| CVE-2026-34909 KEV | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying… | Patch first | 10.0 critical | 1.8% | 2026-05-22 |
| CVE-2019-1129 KEV | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of… | Patch first | 7.8 high | 1.8% | 2019-07-15 |
| CVE-2025-22226 KEV | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with admi… | Patch first | 7.1 high | 1.8% | 2025-03-04 |
| CVE-2025-15556 KEV | Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metad… | Patch first | 7.5 high | 1.7% | 2026-02-03 |
| CVE-2024-21287 KEV | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The support… | Patch first | 7.5 high | 1.7% | 2024-11-18 |
| CVE-2025-21590 KEV | An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to… | Patch first | 4.4 medium | 1.7% | 2025-03-12 |
| CVE-2025-48595 KEV | In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege… | Patch first | 8.4 high | 1.7% | 2026-06-01 |
| CVE-2025-48700 KEV | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Class… | Patch first | 6.1 medium | 1.7% | 2025-06-23 |
| CVE-2019-1130 KEV | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of… | Patch first | 7.8 high | 1.7% | 2019-07-15 |
| CVE-2022-41033 KEV | Windows COM+ Event System Service Elevation of Privilege Vulnerability | Patch first | 7.8 high | 1.7% | 2022-10-11 |
| CVE-2026-72530 KEV | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, a… | Patch first | 9.0 critical | 1.7% | 2026-08-19 |
| CVE-2026-33634 KEV | Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 7… | Patch first | 8.8 high | 1.7% | 2026-03-23 |
| CVE-2023-28229 KEV | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | Patch first | 7.0 high | 1.7% | 2023-04-11 |
| CVE-2024-39891 KEV | In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain p… | Patch first | 5.3 medium | 1.7% | 2024-07-02 |
| CVE-2024-38107 KEV | Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | Patch first | 7.8 high | 1.6% | 2024-08-13 |
| CVE-2025-24989 KEV | An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the… | Patch first | 8.2 high | 1.6% | 2025-02-19 |
| CVE-2026-33824 KEV | Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. | Patch first | 9.8 critical | 1.6% | 2026-04-14 |
| CVE-2025-31277 KEV | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, vi… | Patch first | 8.8 high | 1.6% | 2025-07-30 |
| CVE-2020-11261 KEV | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon… | Patch first | 7.8 high | 1.6% | 2021-06-09 |
| CVE-2021-41357 KEV | Win32k Elevation of Privilege Vulnerability | Patch first | 7.8 high | 1.6% | 2021-10-13 |
| CVE-2021-40450 KEV | Win32k Elevation of Privilege Vulnerability | Patch first | 7.8 high | 1.6% | 2021-10-13 |
| CVE-2025-21418 KEV | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Patch first | 7.8 high | 1.6% | 2025-02-11 |
| CVE-2025-22224 KEV | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with l… | Patch first | 9.3 critical | 1.6% | 2025-03-04 |
| CVE-2025-21334 KEV | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Patch first | 7.8 high | 1.6% | 2025-01-14 |
| CVE-2026-67277 KEV | RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use… | Patch first | 8.2 high | 1.6% | 2026-09-05 |
| CVE-2019-8720 KEV | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution.… | Patch first | 8.8 high | 1.6% | 2023-03-06 |
| CVE-2026-21514 KEV | Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. | Patch first | 7.8 high | 1.5% | 2026-02-10 |
| CVE-2021-1905 KEV | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapd… | Patch first | 8.4 high | 1.5% | 2021-05-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt