peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,503 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

205,455 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-6530 KEV OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions,… Patch first 9.8 critical 96.7% 2018-03-06
CVE-2023-33246 KEV For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, includ… Patch first 9.8 critical 96.6% 2023-05-24
CVE-2026-23760 KEV SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-passwo… Patch first 9.8 critical 96.5% 2026-01-22
CVE-2023-46747 KEV Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the manage… Patch first 9.8 critical 96.5% 2023-10-26
CVE-2026-0257 KEV Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass sec… Patch first 9.1 critical 96.4% 2026-05-13
CVE-2021-35587 KEV Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11… Patch first 9.8 critical 96.3% 2022-01-19
CVE-2020-17530 KEV Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0… Patch first 9.8 critical 95.9% 2020-12-11
CVE-2022-23131 KEV In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user… Patch first 9.1 critical 95.7% 2022-01-13
CVE-2022-41352 KEV An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extra… Patch first 9.8 critical 95.5% 2022-09-26
CVE-2025-12480 KEV Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after set… Patch first 9.1 critical 95.4% 2025-11-10
CVE-2024-1212 KEV Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. Patch first 10.0 critical 95.4% 2024-02-21
CVE-2019-11580 KEV Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthentica… Patch first 9.8 critical 95.4% 2019-06-03
CVE-2019-7609 KEV Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion a… Patch first 10.0 critical 95.3% 2019-03-25
CVE-2024-53704 KEV An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. Patch first 9.8 critical 95.1% 2025-01-09
CVE-2019-10068 KEV An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate… Patch first 9.8 critical 95.1% 2019-03-26
CVE-2023-36845 KEV A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, ne… Patch first 9.8 critical 95.1% 2023-08-17
CVE-2020-2883 KEV Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0… Patch first 9.8 critical 94.9% 2020-04-15
CVE-2025-54309 KEV CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote at… Patch first 9.0 critical 94.9% 2025-07-18
CVE-2024-47575 KEV A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager… Patch first 9.8 critical 94.8% 2024-10-23
CVE-2020-6287 KEV SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker… Patch first 10.0 critical 94.7% 2020-07-14
CVE-2024-21413 KEV Microsoft Outlook Remote Code Execution Vulnerability Patch first 9.8 critical 94.7% 2024-02-13
CVE-2020-14644 KEV Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0… Patch first 9.8 critical 94.5% 2020-07-15
CVE-2025-54236 KEV Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vul… Patch first 9.1 critical 94.5% 2025-09-09
CVE-2017-18368 KEV The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remot… Patch first 9.8 critical 94.4% 2019-05-02
CVE-2025-30406 KEV Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcode… Patch first 9.0 critical 94.3% 2025-04-03
CVE-2024-55591 KEV An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy vers… Patch first 9.8 critical 94.1% 2025-01-14
CVE-2025-11953 KEV The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoi… Patch first 9.8 critical 94% 2025-11-03
CVE-2024-55956 KEV In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash… Patch first 9.8 critical 94% 2024-12-13
CVE-2025-24016 KEV Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an… Patch first 9.9 critical 93.8% 2025-02-10
CVE-2026-21643 KEV An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an un… Patch first 9.8 critical 93.7% 2026-02-06
← previous page 12 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt