peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,528 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

615 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-31200 KEV A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS… Patch first 9.8 critical 18.8% 2025-04-16
CVE-2024-40766 KEV An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource… Patch first 9.8 critical 18.4% 2024-08-23
CVE-2018-0147 KEV A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated,… Patch first 9.8 critical 18.2% 2018-03-08
CVE-2010-5326 KEV The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote atta… Patch first 10.0 critical 17.8% 2016-05-13
CVE-2026-55040 KEV Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. Patch first 9.1 critical 17.5% 2026-07-14
CVE-2020-4006 KEV VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. Patch first 9.1 critical 17.3% 2020-11-23
CVE-2023-26359 KEV Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerabili… Patch first 9.8 critical 17% 2023-03-23
CVE-2023-6345 KEV Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially pe… Patch first 9.6 critical 16.5% 2023-11-29
CVE-2026-58644 KEV Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Patch first 9.8 critical 15.9% 2026-07-14
CVE-2024-4947 KEV Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML p… Patch first 9.6 critical 15.2% 2024-05-15
CVE-2026-34908 KEV A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized cha… Patch first 10.0 critical 15.2% 2026-05-22
CVE-2022-20708 KEV Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… Patch first 10.0 critical 14.9% 2022-02-10
CVE-2026-56291 KEV Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to… Patch first 9.8 critical 14.9% 2026-07-09
CVE-2020-10181 KEV goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) o… Patch first 9.8 critical 14.7% 2020-03-11
CVE-2019-7193 KEV This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend… Patch first 9.8 critical 14.4% 2019-12-05
CVE-2018-0151 KEV A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attac… Patch first 9.8 critical 14.2% 2018-03-28
CVE-2026-82329 KEV JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to… Patch first 9.8 critical 14.1% 2026-08-28
CVE-2026-76460 KEV A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vu… Patch first 10.0 critical 14% 2026-09-16
CVE-2025-31201 KEV This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visi… Patch first 9.8 critical 14% 2025-04-16
CVE-2025-42999 KEV SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialize… Patch first 9.1 critical 13.9% 2025-05-13
CVE-2017-12240 KEV The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote… Patch first 9.8 critical 13.8% 2017-09-29
CVE-2026-22769 KEV Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an… Patch first 10.0 critical 13.3% 2026-02-17
CVE-2026-86218 KEV N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. Patch first 9.8 critical 12.9% 2026-09-06
CVE-2024-21410 KEV Microsoft Exchange Server Elevation of Privilege Vulnerability Patch first 9.8 critical 12.6% 2024-02-13
CVE-2020-8599 KEV Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an ar… Patch first 9.8 critical 11.9% 2020-03-18
CVE-2021-37973 KEV Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially per… Patch first 9.6 critical 11.7% 2021-10-08
CVE-2022-22587 KEV A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS M… Patch first 9.8 critical 11.6% 2022-03-18
CVE-2021-27103 KEV Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later. Patch first 9.8 critical 11.4% 2021-02-16
CVE-2020-15069 KEV Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access.… Patch first 9.8 critical 10.7% 2020-06-29
CVE-2025-6543 KEV Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gatew… Patch first 9.8 critical 10.6% 2025-06-25
← previous page 18 of 21 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt