peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,553 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

902 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-42018 KEV JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing s… Patch first 7.5 high 9.8% 2026-08-12
CVE-2025-6558 KEV Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform… Patch first 8.8 high 9.6% 2025-07-15
CVE-2023-41992 KEV The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attack… Patch first 7.8 high 9.5% 2023-09-21
CVE-2023-23529 KEV A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ve… Patch first 8.8 high 9.5% 2023-02-27
CVE-2021-21206 KEV Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa… Patch first 8.8 high 9.3% 2021-04-26
CVE-2023-42917 KEV A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safar… Patch first 8.8 high 9.3% 2023-11-30
CVE-2021-34486 KEV Windows Event Tracing Elevation of Privilege Vulnerability Patch first 7.8 high 9.3% 2021-08-12
CVE-2022-23748 KEV mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what condi… Patch first 7.8 high 9.1% 2022-11-17
CVE-2021-30563 KEV Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Patch first 8.8 high 8.9% 2021-08-03
CVE-2022-0995 KEV An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of th… Patch first 7.8 high 8.8% 2022-03-25
CVE-2025-43529 KEV A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and i… Patch first 8.8 high 8.8% 2025-12-17
CVE-2026-42016 KEV JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signat… Patch first 8.1 high 8.6% 2026-07-27
CVE-2018-0156 KEV A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigge… Patch first 7.5 high 8.6% 2018-03-28
CVE-2019-1388 KEV An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certi… Patch first 7.8 high 8.6% 2019-11-12
CVE-2022-42856 KEV A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and i… Patch first 8.8 high 8.5% 2022-12-15
CVE-2025-41244 KEV VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges… Patch first 7.8 high 8.4% 2025-09-29
CVE-2021-28310 KEV Win32k Elevation of Privilege Vulnerability Patch first 7.8 high 8.3% 2021-04-13
CVE-2024-38189 KEV Microsoft Project Remote Code Execution Vulnerability Patch first 8.8 high 8.2% 2024-08-13
CVE-2021-38646 KEV Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability Patch first 7.8 high 8% 2021-09-15
CVE-2022-3723 KEV Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.… Patch first 8.8 high 7.9% 2022-11-01
CVE-2023-28434 KEV Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket… Patch first 8.8 high 7.9% 2023-03-22
CVE-2026-18556 KEV Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central… Patch first 7.4 high 7.9% 2026-08-01
CVE-2023-0386 KEV A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s… Patch first 7.8 high 7.9% 2023-03-22
CVE-2021-4102 KEV Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Patch first 8.8 high 7.8% 2022-02-11
CVE-2025-5419 KEV Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a craf… Patch first 8.8 high 7.8% 2025-06-03
CVE-2018-0172 KEV A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remo… Patch first 8.6 high 7.8% 2018-03-28
CVE-2012-2034 KEV Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux;… Patch first 7.5 high 7.8% 2012-06-09
CVE-2018-0155 KEV A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-… Patch first 8.6 high 7.7% 2018-03-28
CVE-2018-0173 KEV A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv… Patch first 8.6 high 7.6% 2018-03-28
CVE-2018-0174 KEV A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remo… Patch first 8.6 high 7.6% 2018-03-28
← previous page 22 of 31 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt