peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-26

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-40684 KEV EXP An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiPr… Patch first 9.8 critical 100% 2022-10-18
CVE-2025-0282 KEV EXP A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for Z… Patch first 9.0 critical 100% 2025-01-08
CVE-2024-4879 KEV EXP ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerabilit… Patch first 9.8 critical 100% 2024-07-10
CVE-2025-31161 KEV EXP CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is use… Patch first 9.8 critical 100% 2025-04-03
CVE-2014-8361 KEV EXP The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the… Patch first 9.8 critical 100% 2015-05-01
CVE-2022-47986 KEV EXP IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserializat… Patch first 9.8 critical 100% 2023-02-17
CVE-2021-42013 KEV EXP It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs… Patch first 9.8 critical 100% 2021-10-07
CVE-2019-2725 KEV EXP Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected a… Patch first 9.8 critical 100% 2019-04-26
CVE-2019-10149 KEV EXP A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c m… Patch first 9.8 critical 100% 2019-06-05
CVE-2018-2628 KEV EXP Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… Patch first 9.8 critical 100% 2018-04-19
CVE-2022-1388 KEV EXP On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5,… Patch first 9.8 critical 100% 2022-05-05
CVE-2018-15961 KEV EXP Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerab… Patch first 9.8 critical 100% 2018-09-25
CVE-2018-10562 KEV EXP An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponFor… Patch first 9.8 critical 99.9% 2018-05-04
CVE-2015-3113 KEV EXP Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468… Patch first 9.8 critical 99.9% 2015-06-23
CVE-2022-30525 KEV EXP A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware ve… Patch first 9.8 critical 99.9% 2022-05-12
CVE-2021-3129 KEV EXP Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure us… Patch first 9.8 critical 99.9% 2021-01-12
CVE-2020-10189 KEV EXP Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the Fi… Patch first 9.8 critical 99.9% 2020-03-06
CVE-2014-7169 KEV EXP GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which… Patch first 9.8 critical 99.9% 2014-09-25
CVE-2022-22963 KEV EXP In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a… Patch first 9.8 critical 99.9% 2022-04-01
CVE-2024-27198 KEV EXP In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible Patch first 9.8 critical 99.9% 2024-03-04
CVE-2025-24813 KEV EXP Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded… Patch first 9.8 critical 99.9% 2025-03-10
CVE-2024-32113 KEV EXP Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 1… Patch first 9.8 critical 99.9% 2024-05-08
CVE-2019-3396 KEV EXP The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the f… Patch first 9.8 critical 99.9% 2019-03-25
CVE-2019-0604 KEV EXP A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka… Patch first 9.8 critical 99.9% 2019-03-05
CVE-2015-1427 KEV EXP The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism an… Patch first 9.8 critical 99.9% 2015-02-17
CVE-2020-7961 KEV EXP Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSO… Patch first 9.8 critical 99.9% 2020-03-20
CVE-2021-22986 KEV EXP On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ… Patch first 9.8 critical 99.9% 2021-03-31
CVE-2014-0497 KEV EXP Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.33… Patch first 9.8 critical 99.9% 2014-02-05
CVE-2022-35914 KEV EXP /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection. Patch first 9.8 critical 99.9% 2022-09-19
CVE-2021-36260 KEV EXP A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vuln… Patch first 9.8 critical 99.9% 2021-09-22
← previous page 2 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt