peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,503 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

450 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-2215 KEV EXP A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this… Patch first 7.8 high 72.1% 2019-10-11
CVE-2017-8540 KEV EXP The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows… Patch first 7.8 high 71.9% 2017-05-26
CVE-2010-4344 KEV EXP Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMT… Patch first 9.8 critical 71.7% 2010-12-14
CVE-2016-2386 KEV EXP SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspeci… Patch first 9.8 critical 71.5% 2016-02-16
CVE-2013-3163 KEV EXP Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch first 8.8 high 70.7% 2013-07-10
CVE-2012-1535 KEV EXP Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers t… Patch first 7.8 high 70.4% 2012-08-15
CVE-2017-6736 KEV EXP The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authent… Patch first 8.8 high 70.4% 2017-07-17
CVE-2018-8453 KEV EXP An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation… Patch first 7.8 high 70% 2018-10-10
CVE-2016-0185 KEV EXP Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Cent… Patch first 7.8 high 69.8% 2016-05-11
CVE-2013-1690 KEV EXP Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle… Patch first 8.8 high 69% 2013-06-26
CVE-2017-6077 KEV EXP ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metac… Patch first 9.8 critical 68.7% 2017-02-22
CVE-2015-4495 KEV EXP The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same… Patch first 8.8 high 68.6% 2015-08-08
CVE-2013-3896 KEV EXP Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to… Patch first 5.5 medium 68% 2013-10-09
CVE-2019-18426 KEV EXP A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site script… Patch first 8.2 high 67.9% 2020-01-21
CVE-2016-4657 KEV EXP WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web… Patch first 8.8 high 66.8% 2016-08-25
CVE-2013-2729 KEV EXP Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code… Patch first 9.8 critical 66.6% 2013-05-16
CVE-2013-0629 KEV EXP Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vecto… Patch first 7.5 high 65.8% 2013-01-09
CVE-2015-7645 KEV EXP Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attack… Patch first 7.8 high 65.3% 2015-10-15
CVE-2019-0211 KEV EXP In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (… Patch first 7.8 high 65% 2019-04-08
CVE-2026-0770 KEV EXP Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote a… Patch first 9.8 critical 63.8% 2026-01-23
CVE-2011-0609 KEV EXP Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android;… Patch first 7.8 high 63.5% 2011-03-15
CVE-2019-8394 KEV EXP Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. Patch first 6.5 medium 63.3% 2019-02-17
CVE-2016-0151 KEV EXP The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 m… Patch first 7.8 high 62.9% 2016-04-12
CVE-2017-0059 KEV EXP Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Inter… Patch first 4.3 medium 62% 2017-03-17
CVE-2019-5786 KEV EXP Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access vi… Patch first 6.5 medium 61.1% 2019-06-27
CVE-2025-32463 KEV EXP Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot op… Patch first 9.3 critical 61% 2025-06-30
CVE-2018-7445 KEV EXP A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the… Patch first 9.8 critical 60.8% 2018-03-19
CVE-2018-6065 KEV EXP Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 al… Patch first 8.8 high 60.3% 2018-11-14
CVE-2020-8655 KEV EXP An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to… Patch first 7.8 high 60.1% 2020-02-07
CVE-2024-21338 KEV EXP Windows Kernel Elevation of Privilege Vulnerability Patch first 7.8 high 59.8% 2024-02-13
← previous page 12 of 15 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt