peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,603 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

1,728 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-39780 KEV On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter… Patch first 8.8 high 40.2% 2023-09-11
CVE-2021-34448 KEV Scripting Engine Memory Corruption Vulnerability Patch first 6.8 medium 40.1% 2021-07-16
CVE-2021-20016 KEV A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username… Patch first 9.8 critical 40% 2021-02-04
CVE-2014-0496 KEV Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execut… Patch first 8.8 high 40% 2014-01-15
CVE-2021-27860 KEV A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a rem… Patch first 9.8 critical 39.8% 2021-12-08
CVE-2025-20352 KEV A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:… Patch first 7.7 high 39.4% 2025-09-24
CVE-2021-1647 KEV Microsoft Defender Remote Code Execution Vulnerability Patch first 7.8 high 39.4% 2021-01-12
CVE-2010-5330 KEV On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized… Patch first 9.8 critical 39.4% 2019-06-11
CVE-2021-26828 KEV OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via v… Patch first 8.8 high 39.4% 2021-06-11
CVE-2020-1464 KEV A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could by… Patch first 7.8 high 38.9% 2020-08-17
CVE-2021-38003 KEV Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a craft… Patch first 8.8 high 38.6% 2021-11-23
CVE-2024-55550 KEV Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient i… Patch first 2.7 low 37.9% 2024-12-10
CVE-2008-0655 KEV Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors. Patch first 8.8 high 37.9% 2008-02-07
CVE-2019-11001 KEV On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to i… Patch first 7.2 high 37.5% 2019-04-08
CVE-2020-17144 KEV Microsoft Exchange Remote Code Execution Vulnerability Patch first 8.4 high 36.5% 2020-12-10
CVE-2018-4990 KEV Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerabil… Patch first 8.8 high 36.2% 2018-07-09
CVE-2021-38163 KEV SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user… Patch first 9.9 critical 36% 2021-09-14
CVE-2022-31199 KEV Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server a… Patch first 9.8 critical 36% 2022-11-08
CVE-2021-39935 KEV An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, a… Patch first 6.8 medium 35.6% 2021-12-13
CVE-2018-17480 KEV Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allo… Patch first 8.8 high 35.6% 2018-12-11
CVE-2022-22960 KEV VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in supp… Patch first 7.8 high 35.5% 2022-04-13
CVE-2020-13671 KEV Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and s… Patch first 8.8 high 35.4% 2020-11-20
CVE-2026-20316 KEV A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log… Patch first 5.3 medium 35.1% 2026-07-29
CVE-2015-1770 KEV Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Unini… Patch first 8.8 high 35% 2015-06-10
CVE-2021-37975 KEV Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Patch first 8.8 high 34.9% 2021-10-08
CVE-2015-2387 KEV ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7… Patch first 7.8 high 34.9% 2015-07-14
CVE-2016-5198 KEV V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisatio… Patch first 8.8 high 34.2% 2017-01-19
CVE-2020-2509 KEV A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrar… Patch first 9.8 critical 34% 2021-04-17
CVE-2022-40799 KEV Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device. Patch first 8.8 high 33.7% 2022-11-29
CVE-2018-13383 KEV A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1… Patch first 4.3 medium 33.6% 2019-05-29
← previous page 34 of 58 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt