peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,648 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

1,728 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-3351 KEV Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Micros… Patch first 6.5 medium 26.3% 2016-09-14
CVE-2021-22506 KEV Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The… Patch first 7.5 high 25.7% 2021-03-26
CVE-2015-2590 KEV Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality… Patch first 9.8 critical 25.5% 2015-07-16
CVE-2023-20269 KEV A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software… Patch first 5.0 medium 25.5% 2023-09-06
CVE-2026-20245 KEV A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Ci… Patch first 7.8 high 25.3% 2026-06-04
CVE-2016-7855 KEV Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to e… Patch first 8.8 high 25.2% 2016-11-01
CVE-2022-0185 KEV A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel ver… Patch first 8.4 high 25.2% 2022-02-11
CVE-2019-18187 KEV Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files fr… Patch first 7.5 high 25.1% 2019-10-28
CVE-2018-5002 KEV Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary c… Patch first 7.8 high 25.1% 2018-07-09
CVE-2024-35250 KEV Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Patch first 7.8 high 25% 2024-06-11
CVE-2026-20122 KEV A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local fi… Patch first 5.4 medium 25% 2026-02-25
CVE-2014-0502 KEV Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2… Patch first 8.8 high 24.8% 2014-02-21
CVE-2022-3038 KEV Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a craft… Patch first 8.8 high 24.7% 2022-09-26
CVE-2022-41128 KEV Windows Scripting Languages Remote Code Execution Vulnerability Patch first 8.8 high 24.6% 2022-11-09
CVE-2023-41993 KEV The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. App… Patch first 8.8 high 24.3% 2023-09-21
CVE-2025-4632 KEV Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to wri… Patch first 9.8 critical 24.3% 2025-05-13
CVE-2026-21510 KEV Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. Patch first 8.8 high 24.2% 2026-02-10
CVE-2016-9563 KEV BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him… Patch first 6.5 medium 24.2% 2016-11-23
CVE-2022-1096 KEV Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Patch first 8.8 high 24.2% 2022-07-23
CVE-2020-1380 KEV A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability co… Patch first 7.8 high 24.2% 2020-08-17
CVE-2021-21166 KEV Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Patch first 8.8 high 24% 2021-03-09
CVE-2026-60004 KEV Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. Patch first 9.8 critical 24% 2026-08-26
CVE-2023-32439 KEV A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ve… Patch first 8.8 high 24% 2023-06-23
CVE-2021-27878 KEV An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which… Patch first 8.8 high 24% 2021-03-01
CVE-2024-27443 KEV An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of… Patch first 6.1 medium 23.6% 2024-08-12
CVE-2025-23006 KEV Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central M… Patch first 9.8 critical 23.4% 2025-01-23
CVE-2021-36948 KEV Windows Update Medic Service Elevation of Privilege Vulnerability Patch first 7.8 high 23.3% 2021-08-12
CVE-2023-28206 KEV An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1,… Patch first 8.6 high 23.2% 2023-04-10
CVE-2024-9680 KEV An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of th… Patch first 9.8 critical 23.2% 2024-10-09
CVE-2015-5317 KEV The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information… Patch first 7.5 high 23% 2015-11-25
← previous page 37 of 58 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt