CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,482 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
169,001 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-67279 KEV | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenti… | Patch first | 6.5 medium | 1% | 2026-09-05 |
| CVE-2026-56164 KEV | Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. | Patch first | 5.3 medium | 1% | 2026-07-14 |
| CVE-2026-32201 KEV | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | Patch first | 6.5 medium | 1% | 2026-04-14 |
| CVE-2021-25370 KEV | An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel pani… | Patch first | 6.1 medium | 0.9% | 2021-03-26 |
| CVE-2021-0920 KEV | In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with… | Patch first | 6.4 medium | 0.8% | 2021-12-15 |
| CVE-2024-50302 KEV | In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by… | Patch first | 5.5 medium | 0.8% | 2024-11-19 |
| CVE-2021-25372 KEV | An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. | Patch first | 6.1 medium | 0.8% | 2021-03-26 |
| CVE-2021-25371 KEV | A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. | Patch first | 6.1 medium | 0.8% | 2021-03-26 |
| CVE-2025-1976 KEV | Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary… | Patch first | 6.7 medium | 0.7% | 2025-04-24 |
| CVE-2026-66384 KEV | An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. | Patch first | 5.3 medium | 0.7% | 2026-08-12 |
| CVE-2026-7473 KEV | On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Ge… | Patch first | 5.8 medium | 0.6% | 2026-06-05 |
| CVE-2025-48928 KEV | The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a p… | Patch first | 4.0 medium | 0.6% | 2025-05-28 |
| CVE-2026-34926 KEV | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the se… | Patch first | 6.7 medium | 0.5% | 2026-05-21 |
| CVE-2021-1906 KEV | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdra… | Patch first | 6.2 medium | 0.5% | 2021-05-07 |
| CVE-2024-29745 KEV | there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution pri… | Patch first | 5.5 medium | 0.5% | 2024-04-05 |
| CVE-2025-43520 KEV | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1,… | Patch first | 5.5 medium | 0.4% | 2025-12-12 |
| CVE-2021-25394 KEV | A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege… | Patch first | 6.4 medium | 0.4% | 2021-06-11 |
| CVE-2022-22265 KEV | An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution… | Patch first | 5.0 medium | 0.4% | 2022-01-10 |
| CVE-2021-25395 KEV | A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is com… | Patch first | 6.4 medium | 0.4% | 2021-06-11 |
| CVE-2023-21237 KEV | In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insuffici… | Patch first | 5.5 medium | 0.3% | 2023-06-28 |
| CVE-2025-48633 KEV | In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in t… | Patch first | 5.5 medium | 0.3% | 2025-12-08 |
| CVE-2008-2938 EXP | Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 a… | Patch early | 4.3 medium | 99.7% | 2008-08-13 |
| CVE-2020-14181 EXP | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabilit… | Patch early | 5.3 medium | 99.6% | 2020-09-17 |
| CVE-2020-16040 EXP | Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a craft… | Patch early | 6.5 medium | 99.6% | 2021-01-08 |
| CVE-2014-0094 EXP | The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is p… | Patch early | 5.0 medium | 99.6% | 2014-03-11 |
| CVE-2021-34429 EXP | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of th… | Patch early | 5.3 medium | 99.3% | 2021-07-15 |
| CVE-2020-11022 EXP | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation… | Patch early | 6.9 medium | 99.2% | 2020-04-29 |
| CVE-2020-9496 EXP | XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 | Patch early | 6.1 medium | 98.9% | 2020-07-15 |
| CVE-2018-15473 EXP | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet… | Patch early | 5.3 medium | 98.6% | 2018-08-17 |
| CVE-2018-11409 EXP | Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by… | Patch early | 5.3 medium | 98.3% | 2018-06-08 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt