peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,483 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

36,453 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-20887 KEV Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks… Patch first 9.8 critical 98.3% 2023-06-07
CVE-2022-26138 KEV The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with… Patch first 9.8 critical 98.2% 2022-07-20
CVE-2020-6207 KEV SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service… Patch first 9.8 critical 98.1% 2020-03-10
CVE-2024-41713 KEV A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated atta… Patch first 9.1 critical 98.1% 2024-10-21
CVE-2023-25717 KEV Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_use… Patch first 9.8 critical 98.1% 2023-02-13
CVE-2024-3272 KEV ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-3… Patch first 9.8 critical 98% 2024-04-04
CVE-2021-35395 KEV Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access po… Patch first 9.8 critical 98% 2021-08-16
CVE-2018-19410 KEV PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator).… Patch first 9.8 critical 97.9% 2018-11-21
CVE-2023-25280 KEV OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_ad… Patch first 9.8 critical 97.9% 2023-03-16
CVE-2021-45382 KEV A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L route… Patch first 9.8 critical 97.8% 2022-02-17
CVE-2021-36380 KEV Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi. Patch first 9.8 critical 97.6% 2021-08-13
CVE-2025-20281 KEV A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the unde… Patch first 10.0 critical 97.6% 2025-06-25
CVE-2021-42237 KEV Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote… Patch first 9.8 critical 97.6% 2021-11-05
CVE-2025-34028 KEV The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expande… Patch first 10.0 critical 97.6% 2025-04-22
CVE-2024-56145 KEV Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this… Patch first 9.8 critical 97.4% 2024-12-18
CVE-2023-24489 KEV A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated att… Patch first 9.8 critical 97.3% 2023-07-10
CVE-2019-5544 KEV OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Criti… Patch first 9.8 critical 97.3% 2019-12-06
CVE-2021-41277 KEV Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->set… Patch first 10.0 critical 97.2% 2021-11-17
CVE-2025-2747 KEV An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for t… Patch first 9.8 critical 97.2% 2025-03-24
CVE-2023-23397 KEV Microsoft Outlook Elevation of Privilege Vulnerability Patch first 9.8 critical 97.2% 2023-03-14
CVE-2024-20439 KEV A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a stat… Patch first 9.8 critical 97.1% 2024-09-04
CVE-2023-38203 KEV Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vul… Patch first 9.8 critical 97.1% 2023-07-20
CVE-2025-54068 KEV Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve… Patch first 9.8 critical 97.1% 2025-07-17
CVE-2018-1273 KEV Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused b… Patch first 9.8 critical 97% 2018-04-11
CVE-2026-20253 KEV In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through… Patch first 9.8 critical 96.9% 2026-06-10
CVE-2025-5086 KEV A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution… Patch first 9.0 critical 96.9% 2025-06-02
CVE-2020-25223 KEV A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11 Patch first 9.8 critical 96.8% 2020-09-25
CVE-2021-22502 KEV Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploi… Patch first 9.8 critical 96.7% 2021-02-08
CVE-2020-1350 KEV A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server… Patch first 10.0 critical 96.7% 2020-07-14
CVE-2018-6530 KEV OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions,… Patch first 9.8 critical 96.7% 2018-03-06
← previous page 10 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt