Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
1,710 results · page 13 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-34192 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | KEVCRITICAL 9.0EPSS 77.3% | 6 July 2023 |
| CVE-2023-21237 | Android Pixel Information Disclosure Vulnerability | KEVMEDIUM 5.5EPSS 0.26% | 28 June 2023 |
| CVE-2023-32439 | Apple Multiple Products WebKit Type Confusion Vulnerability | KEVHIGH 8.8EPSS 23.8% | 23 June 2023 |
| CVE-2023-32435 | Apple Multiple Products WebKit Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 22.8% | 23 June 2023 |
| CVE-2023-32434 | Apple Multiple Products Integer Overflow Vulnerability | KEVHIGH 7.8EPSS 51.5% | 23 June 2023 |
| CVE-2023-32409 | Apple Multiple Products WebKit Sandbox Escape Vulnerability | KEVHIGH 8.6EPSS 16.5% | 23 June 2023 |
| CVE-2023-32373 | Apple Multiple Products WebKit Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 12.2% | 23 June 2023 |
| CVE-2023-28204 | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | KEVMEDIUM 6.5EPSS 14.3% | 23 June 2023 |
| CVE-2023-2533 | PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability | KEVHIGH 8.8EPSS 29.2% | 20 June 2023 |
| CVE-2023-27992 | Zyxel Multiple NAS Devices Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 83.8% | 19 June 2023 |
| CVE-2023-29360 | Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability | KEVHIGH 8.4EPSS 22.1% | 14 June 2023 |
| CVE-2023-29357 | Microsoft SharePoint Server Privilege Escalation Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 14 June 2023 |
| CVE-2023-20867 | VMware Tools Authentication Bypass Vulnerability | KEVLOW 3.9EPSS 13.5% | 13 June 2023 |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 85.7% | 13 June 2023 |
| CVE-2023-20887 | Vmware Aria Operations for Networks Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 98.3% | 7 June 2023 |
| CVE-2023-33538 | TP-Link Multiple Routers Command Injection Vulnerability | KEVHIGH 8.8EPSS 41.9% | 7 June 2023 |
| CVE-2023-3079 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 32.1% | 5 June 2023 |
| CVE-2023-34362 | Progress MOVEit Transfer SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 2 June 2023 |
| CVE-2023-32315 | Ignite Realtime Openfire Path Traversal Vulnerability | KEVHIGH 7.5EPSS 100.0% | 26 May 2023 |
| CVE-2023-2868 | Barracuda Networks ESG Appliance Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 87.7% | 24 May 2023 |
| CVE-2023-33246 | Apache RocketMQ Command Execution Vulnerability | KEVCRITICAL 9.8EPSS 96.6% | 24 May 2023 |
| CVE-2023-33010 | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 28.8% | 24 May 2023 |
| CVE-2023-33009 | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 28.1% | 24 May 2023 |
| CVE-2023-29336 | Microsoft Win32K Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 40.9% | 9 May 2023 |
| CVE-2023-24955 | Microsoft SharePoint Server Code Injection Vulnerability | KEVHIGH 7.2EPSS 85.4% | 9 May 2023 |
| CVE-2023-21492 | Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability | KEVMEDIUM 4.4EPSS 2.55% | 4 May 2023 |
| CVE-2023-29552 | Service Location Protocol (SLP) Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 65.9% | 25 April 2023 |
| CVE-2023-28771 | Zyxel Multiple Firewalls OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.3% | 25 April 2023 |
| CVE-2023-27524 | Apache Superset Insecure Default Initialization of Resource Vulnerability | KEVCRITICAL 9.8EPSS 97.4% | 24 April 2023 |
| CVE-2023-27351 | PaperCut NG/MF Improper Authentication Vulnerability | KEVHIGH 7.5EPSS 78.1% | 20 April 2023 |
| CVE-2023-27350 | PaperCut MF/NG Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 20 April 2023 |
| CVE-2023-2136 | Google Chrome Skia Integer Overflow Vulnerability | KEVCRITICAL 9.6EPSS 5.74% | 19 April 2023 |
| CVE-2023-2033 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 40.8% | 14 April 2023 |
| CVE-2023-20118 | Cisco Small Business RV Series Routers Command Injection Vulnerability | KEVHIGH 7.2EPSS 54.1% | 13 April 2023 |
| CVE-2023-28252 | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 49.0% | 11 April 2023 |
| CVE-2023-28229 | Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability | KEVHIGH 7.0EPSS 1.67% | 11 April 2023 |
| CVE-2023-29492 | Novi Survey Insecure Deserialization Vulnerability | KEVCRITICAL 9.8EPSS 2.69% | 11 April 2023 |
| CVE-2023-28206 | Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability | KEVHIGH 8.6EPSS 23.0% | 10 April 2023 |
| CVE-2023-28205 | Apple Multiple Products WebKit Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 27.1% | 10 April 2023 |
| CVE-2023-26083 | Arm Mali GPU Kernel Driver Information Disclosure Vulnerability | KEVLOW 3.3EPSS 1.22% | 6 April 2023 |
| CVE-2023-1671 | Sophos Web Appliance Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 4 April 2023 |
| CVE-2022-43939 | Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability | KEVCRITICAL 9.8EPSS 92.3% | 3 April 2023 |
| CVE-2022-43769 | Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability | KEVHIGH 7.2EPSS 97.7% | 3 April 2023 |
| CVE-2023-20963 | Android Framework Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 1.47% | 24 March 2023 |
| CVE-2022-42948 | Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 2.71% | 24 March 2023 |
| CVE-2023-26360 | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.6EPSS 97.3% | 23 March 2023 |
| CVE-2023-26359 | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 17.0% | 23 March 2023 |
| CVE-2023-28434 | MinIO Security Feature Bypass Vulnerability | KEVHIGH 8.8EPSS 7.92% | 22 March 2023 |
| CVE-2023-28432 | MinIO Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 84.0% | 22 March 2023 |
| CVE-2023-0386 | Linux Kernel Improper Ownership Management Vulnerability | KEVHIGH 7.8EPSS 7.88% | 22 March 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.