peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,672 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

1,728 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-40890 KEV **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmwa… Patch first 8.8 high 20.7% 2025-02-04
CVE-2014-8439 KEV Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0… Patch first 8.8 high 20.4% 2014-11-25
CVE-2026-48939 KEV A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP… Patch first 9.8 critical 20.1% 2026-06-20
CVE-2016-4171 KEV Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as explo… Patch first 9.8 critical 20.1% 2016-06-16
CVE-2021-21148 KEV Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML… Patch first 8.8 high 20% 2021-02-09
CVE-2021-37976 KEV Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information fr… Patch first 6.5 medium 19.9% 2021-10-08
CVE-2026-93616 KEV A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Manageme… Patch first 9.8 critical 19.7% 2026-09-22
CVE-2025-7775 KEV Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is confi… Patch first 9.8 critical 19.6% 2025-08-26
CVE-2023-36761 KEV Microsoft Word Information Disclosure Vulnerability Patch first 6.5 medium 19.6% 2023-09-12
CVE-2025-66376 KEV Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives… Patch first 7.2 high 19.6% 2026-01-05
CVE-2022-26871 KEV An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which co… Patch first 9.8 critical 19.5% 2022-03-29
CVE-2021-41379 KEV Windows Installer Elevation of Privilege Vulnerability Patch first 5.5 medium 19.5% 2021-11-10
CVE-2024-20359 KEV A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Secur… Patch first 6.0 medium 19.4% 2024-04-24
CVE-2016-1010 KEV Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux,… Patch first 8.8 high 19.3% 2016-03-12
CVE-2025-67038 KEV An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. T… Patch first 9.8 critical 19.3% 2026-03-11
CVE-2016-7836 KEV SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the manag… Patch first 9.8 critical 19.2% 2017-06-09
CVE-2023-7101 KEV Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code executi… Patch first 7.8 high 19.1% 2023-12-24
CVE-2026-72898 KEV Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access t… Patch first 10.0 critical 19% 2026-08-10
CVE-2026-9586 KEV An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning… Patch first 9.8 critical 19% 2026-07-17
CVE-2023-37450 KEV The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9… Patch first 8.8 high 19% 2023-07-27
CVE-2015-5123 KEV Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windo… Patch first 9.8 critical 18.8% 2015-07-14
CVE-2016-7892 KEV Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class.… Patch first 8.8 high 18.8% 2016-12-15
CVE-2014-2120 KEV Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to injec… Patch first 6.1 medium 18.8% 2014-03-19
CVE-2022-22047 KEV Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability Patch first 7.8 high 18.8% 2022-07-12
CVE-2025-31200 KEV A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS… Patch first 9.8 critical 18.8% 2025-04-16
CVE-2020-11899 KEV The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. Patch first 5.4 medium 18.6% 2020-06-17
CVE-2024-7965 KEV Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a craf… Patch first 8.8 high 18.5% 2024-08-21
CVE-2022-22718 KEV Windows Print Spooler Elevation of Privilege Vulnerability Patch first 7.8 high 18.5% 2022-02-09
CVE-2019-5591 KEV A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impers… Patch first 6.5 medium 18.4% 2020-08-14
CVE-2018-8440 KEV An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevat… Patch first 7.8 high 18.4% 2018-09-13
← previous page 39 of 58 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt