peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,519 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

615 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-20753 KEV Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads… Patch first 9.8 critical 29.3% 2019-02-05
CVE-2014-3931 KEV fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption. Patch first 9.8 critical 29% 2017-03-31
CVE-2023-33010 KEV A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmwar… Patch first 9.8 critical 28.8% 2023-05-24
CVE-2018-19949 KEV If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the fol… Patch first 9.8 critical 28.4% 2020-10-28
CVE-2024-11120 KEV Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject an… Patch first 9.8 critical 28.4% 2024-11-15
CVE-2026-76461 KEV A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execu… Patch first 9.8 critical 28.3% 2026-09-14
CVE-2023-33009 KEV A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware… Patch first 9.8 critical 28.1% 2023-05-24
CVE-2020-5135 KEV A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending… Patch first 9.8 critical 26.9% 2020-10-12
CVE-2025-14733 KEV An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code.… Patch first 9.8 critical 26.5% 2025-12-19
CVE-2015-2590 KEV Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality… Patch first 9.8 critical 25.5% 2015-07-16
CVE-2025-4632 KEV Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to wri… Patch first 9.8 critical 24.3% 2025-05-13
CVE-2026-60004 KEV Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. Patch first 9.8 critical 24% 2026-08-26
CVE-2025-23006 KEV Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central M… Patch first 9.8 critical 23.4% 2025-01-23
CVE-2024-9680 KEV An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of th… Patch first 9.8 critical 23.2% 2024-10-09
CVE-2024-37079 KEV vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter S… Patch first 9.8 critical 22.4% 2024-06-18
CVE-2014-0546 KEV Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and conseque… Patch first 9.8 critical 22.3% 2014-08-12
CVE-2016-1019 KEV Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code… Patch first 9.8 critical 22.3% 2016-04-07
CVE-2025-54948 KEV A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and e… Patch first 9.4 critical 22% 2025-08-05
CVE-2025-43300 KEV An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS… Patch first 10.0 critical 22% 2025-08-21
CVE-2024-7971 KEV Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium s… Patch first 9.6 critical 21.1% 2024-08-21
CVE-2026-48939 KEV A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP… Patch first 9.8 critical 20.1% 2026-06-20
CVE-2016-4171 KEV Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as explo… Patch first 9.8 critical 20.1% 2016-06-16
CVE-2026-93616 KEV A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Manageme… Patch first 9.8 critical 19.7% 2026-09-22
CVE-2025-7775 KEV Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is confi… Patch first 9.8 critical 19.6% 2025-08-26
CVE-2022-26871 KEV An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which co… Patch first 9.8 critical 19.5% 2022-03-29
CVE-2025-67038 KEV An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. T… Patch first 9.8 critical 19.3% 2026-03-11
CVE-2016-7836 KEV SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the manag… Patch first 9.8 critical 19.2% 2017-06-09
CVE-2026-72898 KEV Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access t… Patch first 10.0 critical 19% 2026-08-10
CVE-2026-9586 KEV An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning… Patch first 9.8 critical 19% 2026-07-17
CVE-2015-5123 KEV Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windo… Patch first 9.8 critical 18.8% 2015-07-14
← previous page 17 of 21 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt