peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,831 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

1,728 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-20035 KEV Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as… Patch first 6.5 medium 4.2% 2021-09-27
CVE-2023-32049 KEV Windows SmartScreen Security Feature Bypass Vulnerability Patch first 8.8 high 4.2% 2023-07-11
CVE-2019-0859 KEV An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation… Patch first 7.8 high 4.2% 2019-04-09
CVE-2021-30869 KEV A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Se… Patch first 7.8 high 4.1% 2021-08-24
CVE-2026-21533 KEV Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 4.1% 2026-02-10
CVE-2018-0161 KEV A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches… Patch first 6.3 medium 4.1% 2018-03-28
CVE-2022-26501 KEV Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). Patch first 9.8 critical 4.1% 2022-03-17
CVE-2015-1769 KEV Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and… Patch first 6.6 medium 4.1% 2015-08-15
CVE-2025-2749 KEV An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative l… Patch first 7.2 high 4.1% 2025-03-24
CVE-2026-3055 KEV Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread Patch first 9.8 critical 4% 2026-03-23
CVE-2021-36955 KEV Windows Common Log File System Driver Elevation of Privilege Vulnerability Patch first 7.8 high 4% 2021-09-15
CVE-2024-26169 KEV Windows Error Reporting Service Elevation of Privilege Vulnerability Patch first 7.8 high 4% 2024-03-12
CVE-2019-7483 KEV In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a f… Patch first 7.5 high 4% 2019-12-19
CVE-2024-39717 KEV The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with P… Patch first 7.2 high 4% 2024-08-22
CVE-2021-27137 KEV An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticate… Patch first 8.1 high 4% 2026-07-16
CVE-2025-27915 KEV An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic W… Patch first 5.4 medium 4% 2025-03-12
CVE-2026-75650 KEV Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary co… Patch first 10.0 critical 3.9% 2026-09-07
CVE-2024-30040 KEV Windows MSHTML Platform Security Feature Bypass Vulnerability Patch first 8.8 high 3.9% 2024-05-14
CVE-2024-20953 KEV Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily ex… Patch first 8.8 high 3.9% 2024-02-17
CVE-2023-43000 KEV A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6… Patch first 8.8 high 3.9% 2025-11-05
CVE-2025-25249 KEV A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS… Patch first 8.1 high 3.9% 2026-01-13
CVE-2025-24985 KEV Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. Patch first 7.8 high 3.8% 2025-03-11
CVE-2026-82078 KEV An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates… Patch first 9.1 critical 3.8% 2026-08-28
CVE-2024-9537 KEV ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vuln… Patch first 9.8 critical 3.8% 2024-10-18
CVE-2024-0519 KEV Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a craf… Patch first 8.8 high 3.8% 2024-01-16
CVE-2023-41061 KEV A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attach… Patch first 7.8 high 3.8% 2023-09-07
CVE-2025-24201 KEV An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and… Patch first 10.0 critical 3.8% 2025-03-11
CVE-2020-3566 KEV A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote atta… Patch first 8.6 high 3.7% 2020-08-29
CVE-2023-0266 KEV A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be us… Patch first 7.9 high 3.7% 2023-01-30
CVE-2021-30665 KEV A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6,… Patch first 8.8 high 3.7% 2021-09-08
← previous page 49 of 58 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt