CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,903 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
398,903 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-93952 KEV | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and… | Patch first | 10.0 critical | 1.1% | 2026-09-22 |
| CVE-2022-22706 KEV | Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, B… | Patch first | 7.8 high | 1.1% | 2022-03-03 |
| CVE-2026-45321 KEV | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The… | Patch first | 9.6 critical | 1.1% | 2026-05-12 |
| CVE-2022-42827 KEV | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16.… | Patch first | 7.8 high | 1% | 2022-11-01 |
| CVE-2026-67279 KEV | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenti… | Patch first | 6.5 medium | 1% | 2026-09-05 |
| CVE-2026-88771 KEV | Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-… | Patch first | 9.8 critical | 1% | 2026-09-27 |
| CVE-2026-3910 KEV | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a… | Patch first | 8.8 high | 1% | 2026-03-13 |
| CVE-2021-23874 KEV | Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execut… | Patch first | 8.2 high | 1% | 2021-02-10 |
| CVE-2025-22225 KEV | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write… | Patch first | 8.2 high | 1% | 2025-03-04 |
| CVE-2025-27038 KEV | Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. | Patch first | 7.5 high | 1% | 2025-06-03 |
| CVE-2026-8452 KEV | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the applianc… | Patch first | 9.8 critical | 1% | 2026-06-30 |
| CVE-2026-48172 KEV | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best… | Patch first | 9.8 critical | 1% | 2026-05-21 |
| CVE-2026-56164 KEV | Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. | Patch first | 5.3 medium | 1% | 2026-07-14 |
| CVE-2026-20349 KEV | A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Th… | Patch first | 8.6 high | 1% | 2026-08-11 |
| CVE-2026-16812 KEV | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and… | Patch first | 10.0 critical | 1% | 2026-07-27 |
| CVE-2021-1048 KEV | In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privil… | Patch first | 7.8 high | 1% | 2021-12-15 |
| CVE-2025-39964 KEV | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes… | Patch first | 7.8 high | 1% | 2025-10-13 |
| CVE-2026-32201 KEV | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | Patch first | 6.5 medium | 1% | 2026-04-14 |
| CVE-2026-8398 KEV | A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distribu… | Patch first | 9.8 critical | 1% | 2026-05-15 |
| CVE-2023-42824 KEV | The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privi… | Patch first | 7.8 high | 0.9% | 2023-10-04 |
| CVE-2026-84869 KEV | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host… | Patch first | 9.9 critical | 0.9% | 2026-09-08 |
| CVE-2023-33106 KEV | Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. | Patch first | 8.4 high | 0.9% | 2023-12-05 |
| CVE-2023-33107 KEV | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. | Patch first | 8.4 high | 0.9% | 2023-12-05 |
| CVE-2021-25370 KEV | An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel pani… | Patch first | 6.1 medium | 0.9% | 2021-03-26 |
| CVE-2026-55255 KEV | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerabilit… | Patch first | 8.4 high | 0.9% | 2026-06-23 |
| CVE-2021-44168 KEV | A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authentica… | Patch first | 3.3 low | 0.9% | 2022-01-04 |
| CVE-2025-21479 KEV | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | Patch first | 8.6 high | 0.8% | 2025-06-03 |
| CVE-2026-59822 KEV | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed… | Patch first | 8.2 high | 0.8% | 2026-07-08 |
| CVE-2020-9859 KEV | A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Su… | Patch first | 7.8 high | 0.8% | 2020-06-05 |
| CVE-2021-0920 KEV | In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with… | Patch first | 6.4 medium | 0.8% | 2021-12-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt