peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,558 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

902 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-30869 KEV A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Se… Patch first 7.8 high 4.1% 2021-08-24
CVE-2026-21533 KEV Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 4.1% 2026-02-10
CVE-2025-48384 KEV Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full acce… Patch first 8.0 high 4.1% 2025-07-08
CVE-2025-2749 KEV An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative l… Patch first 7.2 high 4.1% 2025-03-24
CVE-2021-36955 KEV Windows Common Log File System Driver Elevation of Privilege Vulnerability Patch first 7.8 high 4% 2021-09-15
CVE-2024-26169 KEV Windows Error Reporting Service Elevation of Privilege Vulnerability Patch first 7.8 high 4% 2024-03-12
CVE-2019-7483 KEV In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a f… Patch first 7.5 high 4% 2019-12-19
CVE-2024-39717 KEV The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with P… Patch first 7.2 high 4% 2024-08-22
CVE-2021-27137 KEV An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticate… Patch first 8.1 high 4% 2026-07-16
CVE-2024-30040 KEV Windows MSHTML Platform Security Feature Bypass Vulnerability Patch first 8.8 high 3.9% 2024-05-14
CVE-2024-20953 KEV Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily ex… Patch first 8.8 high 3.9% 2024-02-17
CVE-2023-43000 KEV A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6… Patch first 8.8 high 3.9% 2025-11-05
CVE-2025-25249 KEV A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS… Patch first 8.1 high 3.9% 2026-01-13
CVE-2025-24985 KEV Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. Patch first 7.8 high 3.8% 2025-03-11
CVE-2024-0519 KEV Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a craf… Patch first 8.8 high 3.8% 2024-01-16
CVE-2023-41061 KEV A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attach… Patch first 7.8 high 3.8% 2023-09-07
CVE-2020-3566 KEV A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote atta… Patch first 8.6 high 3.7% 2020-08-29
CVE-2023-0266 KEV A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be us… Patch first 7.9 high 3.7% 2023-01-30
CVE-2021-30665 KEV A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6,… Patch first 8.8 high 3.7% 2021-09-08
CVE-2021-31010 KEV A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and… Patch first 7.5 high 3.7% 2021-08-24
CVE-2018-19321 KEV The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.2… Patch first 7.8 high 3.7% 2018-12-21
CVE-2021-27102 KEV Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later. Patch first 7.8 high 3.7% 2021-02-16
CVE-2026-85880 KEV Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 3.6% 2026-09-08
CVE-2016-8562 KEV A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special condit… Patch first 7.5 high 3.6% 2016-11-18
CVE-2019-1385 KEV An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in acce… Patch first 7.8 high 3.6% 2019-11-12
CVE-2018-19320 KEV The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GUR… Patch first 7.8 high 3.6% 2018-12-21
CVE-2024-53197 KEV In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices… Patch first 7.8 high 3.6% 2024-12-27
CVE-2023-45727 KEV Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and ea… Patch first 7.5 high 3.5% 2023-10-18
CVE-2025-3935 KEV ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserv… Patch first 8.1 high 3.5% 2025-04-25
CVE-2021-30663 KEV An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 1… Patch first 8.8 high 3.5% 2021-09-08
← previous page 25 of 31 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt