peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,806 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

1,728 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-16256 KEV Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location an… Patch first 9.8 critical 4.9% 2019-09-12
CVE-2021-38000 KEV Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily brows… Patch first 6.1 medium 4.9% 2021-11-23
CVE-2018-0179 KEV Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trig… Patch first 5.9 medium 4.9% 2018-03-28
CVE-2018-0180 KEV Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trig… Patch first 5.9 medium 4.9% 2018-03-28
CVE-2025-47827 KEV In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a cr… Patch first 4.6 medium 4.9% 2025-06-05
CVE-2009-1123 KEV The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate ch… Patch first 7.8 high 4.9% 2009-06-10
CVE-2020-1631 KEV A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirec… Patch first 8.8 high 4.8% 2020-05-04
CVE-2004-1464 KEV Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP co… Patch first 5.9 medium 4.8% 2004-12-31
CVE-2026-21525 KEV Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. Patch first 6.2 medium 4.8% 2026-02-10
CVE-2013-3993 KEV IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted da… Patch first 6.5 medium 4.8% 2014-07-07
CVE-2019-18988 KEV TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installation… Patch first 7.0 high 4.7% 2020-02-07
CVE-2012-0518 KEV Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to… Patch first 4.7 medium 4.7% 2012-10-16
CVE-2020-29574 KEV An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements… Patch first 9.8 critical 4.7% 2020-12-11
CVE-2025-60710 KEV Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges l… Patch first 7.8 high 4.6% 2025-11-11
CVE-2019-7287 KEV A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbit… Patch first 7.8 high 4.6% 2019-12-18
CVE-2020-1027 KEV An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privileg… Patch first 7.8 high 4.5% 2020-04-15
CVE-2026-20045 KEV A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME)… Patch first 8.2 high 4.5% 2026-01-21
CVE-2021-31979 KEV Windows Kernel Elevation of Privilege Vulnerability Patch first 7.8 high 4.5% 2021-07-14
CVE-2022-2856 KEV Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily bro… Patch first 6.5 medium 4.5% 2022-09-26
CVE-2025-54313 KEV eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package exe… Patch first 7.5 high 4.5% 2025-07-19
CVE-2021-30661 KEV A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchO… Patch first 8.8 high 4.5% 2021-09-08
CVE-2026-81578 KEV An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthentic… Patch first 9.8 critical 4.5% 2026-08-28
CVE-2023-46748 KEV An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network acces… Patch first 8.8 high 4.5% 2023-10-26
CVE-2025-24200 KEV An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.… Patch first 6.1 medium 4.5% 2025-02-10
CVE-2020-2021 KEV When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecke… Patch first 10.0 critical 4.4% 2020-06-29
CVE-2024-20399 KEV A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary c… Patch first 6.0 medium 4.3% 2024-07-01
CVE-2025-55177 KEV Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, an… Patch first 5.4 medium 4.3% 2025-08-29
CVE-2023-41179 KEV A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Fr… Patch first 7.2 high 4.3% 2023-09-19
CVE-2025-48384 KEV Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full acce… Patch first 8.0 high 4.2% 2025-07-08
CVE-2018-8611 KEV An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Pr… Patch first 7.8 high 4.2% 2018-12-12
← previous page 48 of 58 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt