peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-26

168,978 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-26086 KEV EXP Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /… Patch first 5.3 medium 100% 2021-08-16
CVE-2021-22204 KEV EXP Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicio… Patch first 6.8 medium 100% 2021-04-23
CVE-2021-26085 KEV EXP Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulne… Patch first 5.3 medium 99.9% 2021-08-03
CVE-2025-4427 KEV EXP An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources with… Patch first 5.3 medium 99.9% 2025-05-13
CVE-2023-23752 KEV EXP An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. Patch first 5.3 medium 99.8% 2023-02-16
CVE-2020-1472 KEV EXP An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, us… Patch first 5.5 medium 99.4% 2020-08-17
CVE-2013-0431 KEV EXP Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted r… Patch first 5.3 medium 90.2% 2013-01-31
CVE-2009-3960 KEV EXP Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex… Patch first 6.5 medium 90.1% 2010-02-15
CVE-2020-11652 KEV EXP An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some metho… Patch first 6.5 medium 86.2% 2020-04-30
CVE-2020-11023 KEV EXP In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sani… Patch first 6.9 medium 84.9% 2020-04-29
CVE-2010-0738 KEV EXP The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 bef… Patch first 5.3 medium 79.4% 2010-04-28
CVE-2016-3718 KEV EXP The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (S… Patch first 5.5 medium 76.7% 2016-05-05
CVE-2016-3715 KEV EXP The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. Patch first 5.5 medium 75.3% 2016-05-05
CVE-2024-37383 KEV EXP Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. Patch first 6.1 medium 73.3% 2024-06-07
CVE-2019-9978 KEV EXP The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as explo… Patch first 6.1 medium 72.9% 2019-03-24
CVE-2013-3896 KEV EXP Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to… Patch first 5.5 medium 68% 2013-10-09
CVE-2019-8394 KEV EXP Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. Patch first 6.5 medium 63.3% 2019-02-17
CVE-2017-0059 KEV EXP Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Inter… Patch first 4.3 medium 62% 2017-03-17
CVE-2019-5786 KEV EXP Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access vi… Patch first 6.5 medium 61.1% 2019-06-27
CVE-2025-24054 KEV EXP External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. Patch first 6.5 medium 58.9% 2025-03-11
CVE-2019-5825 KEV EXP Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafte… Patch first 6.5 medium 55.9% 2019-11-25
CVE-2016-2388 KEV EXP The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP requ… Patch first 5.3 medium 52.2% 2016-02-16
CVE-2013-5223 KEV EXP Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web scr… Patch first 5.4 medium 50.8% 2013-11-19
CVE-2018-13374 KEV EXP A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LD… Patch first 4.3 medium 37.8% 2019-01-22
CVE-2016-4655 KEV EXP The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app. Patch first 5.5 medium 33.4% 2016-08-25
CVE-2018-2380 KEV EXP SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characte… Patch first 6.6 medium 28.9% 2018-03-01
CVE-2014-0196 KEV EXP The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST"… Patch first 5.5 medium 22.5% 2014-05-07
CVE-2015-3246 KEV EXP libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allow… Patch first 5.1 medium 8.8% 2015-08-11
CVE-2026-32202 KEV EXP Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. Patch first 4.3 medium 4.9% 2026-04-14
CVE-2021-31207 KEV Microsoft Exchange Server Security Feature Bypass Vulnerability Patch first 6.6 medium 99.8% 2021-05-11
page 1 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt