peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,587 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

902 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-55255 KEV Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerabilit… Patch first 8.4 high 0.9% 2026-06-23
CVE-2025-21479 KEV Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. Patch first 8.6 high 0.8% 2025-06-03
CVE-2026-59822 KEV LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed… Patch first 8.2 high 0.8% 2026-07-08
CVE-2020-9859 KEV A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Su… Patch first 7.8 high 0.8% 2020-06-05
CVE-2026-54420 KEV LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web sh… Patch first 8.5 high 0.8% 2026-06-14
CVE-2024-4610 KEV Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improp… Patch first 7.8 high 0.8% 2024-06-07
CVE-2024-43093 KEV In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive direct… Patch first 7.3 high 0.7% 2024-11-13
CVE-2026-53362 KEV In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), w… Patch first 7.8 high 0.7% 2026-07-04
CVE-2026-3909 KEV Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTM… Patch first 8.8 high 0.7% 2026-03-13
CVE-2026-5281 KEV Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrar… Patch first 8.8 high 0.7% 2026-04-01
CVE-2019-8526 KEV A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain… Patch first 7.8 high 0.7% 2019-12-18
CVE-2023-33063 KEV Memory corruption in DSP Services during a remote call from HLOS to DSP. Patch first 7.8 high 0.7% 2023-12-05
CVE-2021-39793 KEV In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local… Patch first 7.8 high 0.7% 2022-03-16
CVE-2024-43047 KEV Memory corruption while maintaining memory maps of HLOS memory. Patch first 7.8 high 0.7% 2024-10-07
CVE-2024-29748 KEV there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pri… Patch first 7.8 high 0.7% 2024-04-05
CVE-2026-53266 KEV In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target k… Patch first 8.8 high 0.6% 2026-06-25
CVE-2021-25487 KEV Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in ar… Patch first 7.3 high 0.6% 2021-10-06
CVE-2026-58704 KEV In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of… Patch first 8.8 high 0.6% 2026-09-15
CVE-2025-48543 KEV In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to lo… Patch first 8.8 high 0.5% 2025-09-04
CVE-2026-42897 KEV Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to p… Patch first 8.1 high 0.5% 2026-05-14
CVE-2022-48618 KEV The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker… Patch first 7.0 high 0.5% 2024-01-09
CVE-2025-21480 KEV Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. Patch first 8.6 high 0.5% 2025-06-03
CVE-2022-22071 KEV Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapd… Patch first 8.4 high 0.5% 2022-06-14
CVE-2026-41091 KEV Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 0.4% 2026-05-20
CVE-2026-33825 KEV Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 0.4% 2026-04-14
CVE-2026-81963 KEV Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 0.4% 2026-09-08
CVE-2025-43510 KEV A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26… Patch first 7.8 high 0.4% 2025-12-12
CVE-2026-56155 KEV Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally… Patch first 7.8 high 0.3% 2026-07-14
CVE-2026-68820 KEV Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Patch first 7.0 high 0.3% 2026-08-11
CVE-2026-3502 KEV TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update deli… Patch first 7.8 high 0.3% 2026-03-30
← previous page 30 of 31 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt