peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,502 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

317,898 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-45195 KEV Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade… Patch first 7.5 high 100% 2024-09-04
CVE-2023-4863 KEV Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memor… Patch first 8.8 high 100% 2023-09-12
CVE-2024-24919 KEV Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote A… Patch first 8.6 high 100% 2024-05-28
CVE-2022-41082 KEV Microsoft Exchange Server Remote Code Execution Vulnerability Patch first 8.0 high 100% 2022-10-03
CVE-2022-41040 KEV Microsoft Exchange Server Elevation of Privilege Vulnerability Patch first 8.8 high 100% 2022-10-03
CVE-2024-29824 KEV An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network… Patch first 8.8 high 99.9% 2024-05-31
CVE-2019-7481 KEV Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 ver… Patch first 7.5 high 99.9% 2019-12-17
CVE-2023-21839 KEV Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.… Patch first 7.5 high 99.9% 2023-01-18
CVE-2023-38831 KEV RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs… Patch first 7.8 high 99.8% 2023-08-23
CVE-2021-34527 KEV A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who su… Patch first 8.8 high 99.8% 2021-07-02
CVE-2023-29298 KEV Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vul… Patch first 7.5 high 99.8% 2023-07-12
CVE-2021-31207 KEV Microsoft Exchange Server Security Feature Bypass Vulnerability Patch first 6.6 medium 99.8% 2021-05-11
CVE-2023-38205 KEV Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerabilit… Patch first 7.5 high 99.7% 2023-09-14
CVE-2021-22054 KEV VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 cont… Patch first 7.5 high 99.7% 2021-12-17
CVE-2024-21412 KEV Internet Shortcut Files Security Feature Bypass Vulnerability Patch first 8.1 high 99.4% 2024-02-13
CVE-2022-30190 KEV A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who succe… Patch first 7.8 high 99.2% 2022-06-01
CVE-2022-30333 KEV RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by c… Patch first 7.5 high 99.1% 2022-05-09
CVE-2025-49706 KEV Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Patch first 6.5 medium 99.1% 2025-07-08
CVE-2023-36884 KEV Windows Search Remote Code Execution Vulnerability Patch first 7.5 high 98.9% 2023-07-11
CVE-2022-27925 KEV Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated us… Patch first 7.2 high 98.7% 2022-04-21
CVE-2024-29059 KEV .NET Framework Information Disclosure Vulnerability Patch first 7.5 high 98.6% 2024-03-23
CVE-2024-9463 KEV An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expe… Patch first 7.5 high 98.5% 2024-10-09
CVE-2021-21311 KEV Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forg… Patch first 7.2 high 98.5% 2021-02-11
CVE-2021-33766 KEV Microsoft Exchange Server Information Disclosure Vulnerability Patch first 7.3 high 98.1% 2021-07-14
CVE-2021-39144 KEV XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffic… Patch first 8.5 high 98.1% 2021-08-23
CVE-2024-12987 KEV A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /… Patch first 7.3 high 98.1% 2024-12-27
CVE-2020-14883 KEV Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.… Patch first 7.2 high 97.9% 2020-10-21
CVE-2020-25078 KEV An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint all… Patch first 7.5 high 97.5% 2020-09-02
CVE-2021-40444 KEV Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted a… Patch first 8.8 high 97.5% 2021-09-15
CVE-2023-26360 KEV Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that c… Patch first 8.6 high 97.3% 2023-03-23
← previous page 10 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt