CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,882 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
398,882 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-2597 KEV | Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcom… | Patch first | 8.4 high | 1.5% | 2014-08-31 |
| CVE-2021-36742 KEV | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allo… | Patch first | 7.8 high | 1.5% | 2021-07-29 |
| CVE-2024-23225 KEV | A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS… | Patch first | 7.8 high | 1.5% | 2024-03-05 |
| CVE-2023-20963 KEV | In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. U… | Patch first | 7.8 high | 1.5% | 2023-03-24 |
| CVE-2026-72529 KEV | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, a… | Patch first | 9.8 critical | 1.5% | 2026-08-19 |
| CVE-2019-1214 KEV | An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Window… | Patch first | 7.8 high | 1.4% | 2019-09-11 |
| CVE-2024-23296 KEV | A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS… | Patch first | 7.8 high | 1.4% | 2024-03-05 |
| CVE-2025-32701 KEV | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | Patch first | 7.8 high | 1.4% | 2025-05-13 |
| CVE-2025-21335 KEV | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Patch first | 7.8 high | 1.4% | 2025-01-14 |
| CVE-2023-41990 KEV | The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big… | Patch first | 7.8 high | 1.4% | 2023-09-12 |
| CVE-2020-0069 KEV | In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing… | Patch first | 7.8 high | 1.4% | 2020-03-10 |
| CVE-2024-53150 KEV | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current… | Patch first | 7.1 high | 1.4% | 2024-12-24 |
| CVE-2025-24983 KEV | Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | Patch first | 7.0 high | 1.3% | 2025-03-11 |
| CVE-2026-20700 KEV | A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3,… | Patch first | 7.8 high | 1.3% | 2026-02-11 |
| CVE-2026-48027 KEV | Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed… | Patch first | 9.8 critical | 1.3% | 2026-05-27 |
| CVE-2025-35939 KEV | Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an… | Patch first | 5.3 medium | 1.3% | 2025-05-07 |
| CVE-2024-49035 KEV | An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. | Patch first | 8.7 high | 1.3% | 2024-11-26 |
| CVE-2023-4346 KEV | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users bei… | Patch first | 7.5 high | 1.3% | 2023-08-29 |
| CVE-2025-38352 KEV | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_… | Patch first | 7.8 high | 1.3% | 2025-07-22 |
| CVE-2026-45498 KEV | Microsoft Defender Denial of Service Vulnerability | Patch first | 4.0 medium | 1.3% | 2026-05-20 |
| CVE-2026-21385 KEV | Memory corruption while using alignments for memory allocation. | Patch first | 7.8 high | 1.2% | 2026-03-02 |
| CVE-2026-88772 KEV | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F… | Patch first | 8.1 high | 1.2% | 2026-09-27 |
| CVE-2026-65400 KEV | An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma… | Patch first | 9.8 critical | 1.2% | 2026-08-06 |
| CVE-2023-26083 KEV | Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all version… | Patch first | 3.3 low | 1.2% | 2023-04-06 |
| CVE-2025-59374 KEV | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supp… | Patch first | 9.8 critical | 1.2% | 2025-12-17 |
| CVE-2025-43200 KEV | This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPa… | Patch first | 4.2 medium | 1.2% | 2025-06-16 |
| CVE-2022-22674 KEV | An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixe… | Patch first | 5.5 medium | 1.1% | 2022-05-26 |
| CVE-2023-36851 KEV | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attac… | Patch first | 5.3 medium | 1.1% | 2023-09-27 |
| CVE-2023-4211 KEV | A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. | Patch first | 5.5 medium | 1.1% | 2023-10-01 |
| CVE-2021-25369 KEV | An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. | Patch first | 6.2 medium | 1.1% | 2021-03-26 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt