peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,483 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

148,897 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-52163 KEV Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer s… Patch first 8.8 high 96.9% 2025-02-03
CVE-2015-1641 KEV Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Autom… Patch first 7.8 high 96.7% 2015-04-14
CVE-2024-57727 KEV SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attac… Patch first 7.5 high 96.6% 2025-01-15
CVE-2020-8260 KEV A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution u… Patch first 7.2 high 96.5% 2020-10-28
CVE-2021-20124 KEV A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthe… Patch first 7.5 high 96.3% 2021-10-13
CVE-2017-3506 KEV Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected a… Patch first 7.4 high 96.3% 2017-04-24
CVE-2025-61884 KEV Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-… Patch first 7.5 high 95.9% 2025-10-12
CVE-2021-26857 KEV Microsoft Exchange Server Remote Code Execution Vulnerability Patch first 7.8 high 95.8% 2021-03-03
CVE-2020-5410 KEV Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrar… Patch first 7.5 high 95.6% 2020-06-02
CVE-2024-1708 KEV ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote c… Patch first 8.4 high 95.4% 2024-02-21
CVE-2022-36537 KEV ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the com… Patch first 7.5 high 95.4% 2022-08-26
CVE-2018-0798 KEV Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulne… Patch first 8.8 high 95.1% 2018-01-10
CVE-2017-12637 KEV Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote at… Patch first 7.5 high 95.1% 2017-08-07
CVE-2024-9474 KEV A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface t… Patch first 7.2 high 94.7% 2024-11-18
CVE-2024-48248 KEV NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to rem… Patch first 8.6 high 94.4% 2025-03-04
CVE-2025-8088 KEV A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive fi… Patch first 8.8 high 94.1% 2025-08-08
CVE-2025-4008 KEV The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system throu… Patch first 8.8 high 93.7% 2025-05-21
CVE-2021-26858 KEV Microsoft Exchange Server Remote Code Execution Vulnerability Patch first 7.8 high 93.7% 2021-03-03
CVE-2018-0802 KEV Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulner… Patch first 7.8 high 93.3% 2018-01-10
CVE-2022-33891 KEV The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks w… Patch first 8.8 high 93.1% 2022-07-18
CVE-2025-34291 KEV Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permiss… Patch first 8.8 high 92.8% 2025-12-05
CVE-2023-38950 KEV A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a cra… Patch first 7.5 high 92.5% 2023-08-03
CVE-2025-11371 KEV In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows u… Patch first 7.5 high 92.1% 2025-10-09
CVE-2024-7399 KEV Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to wri… Patch first 8.8 high 91.9% 2024-08-12
CVE-2021-42321 KEV Microsoft Exchange Server Remote Code Execution Vulnerability Patch first 8.8 high 91.7% 2021-11-10
CVE-2020-8243 KEV A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform a… Patch first 7.2 high 90.8% 2020-09-30
CVE-2021-21315 KEV The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,… Patch first 7.1 high 90.7% 2021-02-16
CVE-2025-6218 KEV RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… Patch first 7.8 high 90.5% 2025-06-21
CVE-2021-32648 KEV octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account… Patch first 8.2 high 90.4% 2021-08-26
CVE-2021-20123 KEV A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. A… Patch first 7.5 high 90.2% 2021-10-13
← previous page 10 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt