peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,529 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

902 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-15410 KEV Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Co… Patch first 7.2 high 11.8% 2026-07-14
CVE-2026-73570 KEV A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP… Patch first 8.9 high 11.7% 2026-08-13
CVE-2020-3118 KEV A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute… Patch first 8.8 high 11.7% 2020-02-05
CVE-2021-38648 KEV Open Management Infrastructure Elevation of Privilege Vulnerability Patch first 7.8 high 11.4% 2021-09-15
CVE-2017-6740 KEV The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authent… Patch first 8.8 high 11.1% 2017-07-17
CVE-2013-0648 KEV Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on… Patch first 8.8 high 11.1% 2013-02-27
CVE-2017-0005 KEV The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 201… Patch first 7.8 high 11% 2017-03-17
CVE-2024-4761 KEV Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HT… Patch first 8.8 high 11% 2024-05-14
CVE-2021-30762 KEV A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content ma… Patch first 8.8 high 11% 2021-09-08
CVE-2020-8467 KEV A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arb… Patch first 8.8 high 10.9% 2020-03-18
CVE-2017-6738 KEV The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authent… Patch first 8.8 high 10.9% 2017-07-17
CVE-2017-6739 KEV A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely ex… Patch first 8.8 high 10.9% 2017-07-17
CVE-2017-6743 KEV The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authent… Patch first 8.8 high 10.9% 2017-07-17
CVE-2023-23376 KEV Windows Common Log File System Driver Elevation of Privilege Vulnerability Patch first 7.8 high 10.9% 2023-02-14
CVE-2022-23176 KEV WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session… Patch first 8.8 high 10.8% 2022-02-24
CVE-2026-83549 KEV Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in th… Patch first 7.8 high 10.8% 2026-09-01
CVE-2022-26925 KEV Windows LSA Spoofing Vulnerability Patch first 8.1 high 10.7% 2022-05-10
CVE-2024-23222 KEV A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.… Patch first 8.8 high 10.6% 2024-01-23
CVE-2020-6572 KEV Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page. Patch first 8.8 high 10.6% 2021-01-14
CVE-2021-30761 KEV A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content… Patch first 8.8 high 10.5% 2021-09-08
CVE-2013-0643 KEV The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x bef… Patch first 8.8 high 10.5% 2013-02-27
CVE-2020-27932 KEV A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9… Patch first 7.8 high 10.3% 2020-12-08
CVE-2021-43890 KEV We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt… Patch first 7.1 high 10.3% 2021-12-15
CVE-2021-33771 KEV Windows Kernel Elevation of Privilege Vulnerability Patch first 7.8 high 10.2% 2021-07-14
CVE-2015-2546 KEV The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012… Patch first 8.2 high 10.1% 2015-09-09
CVE-2024-44308 KEV The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS… Patch first 8.8 high 10.1% 2024-11-20
CVE-2020-3433 KEV A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, l… Patch first 7.8 high 10% 2020-08-17
CVE-2023-32046 KEV Windows MSHTML Platform Elevation of Privilege Vulnerability Patch first 7.8 high 10% 2023-07-11
CVE-2022-32893 KEV An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1,… Patch first 8.8 high 9.9% 2022-08-24
CVE-2021-21193 KEV Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… Patch first 8.8 high 9.9% 2021-03-16
← previous page 21 of 31 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt