peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,503 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

36,454 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-21762 KEV A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through… Patch first 9.8 critical 83.4% 2024-02-09
CVE-2019-7194 KEV This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP reco… Patch first 9.8 critical 83.1% 2019-12-05
CVE-2020-3992 KEV OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-… Patch first 9.8 critical 83% 2020-10-20
CVE-2024-42009 KEV A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim… Patch first 9.3 critical 82.9% 2024-08-05
CVE-2021-27561 KEV Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication. Patch first 9.8 critical 82.9% 2021-10-15
CVE-2023-27992 KEV The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior… Patch first 9.8 critical 82.8% 2023-06-19
CVE-2023-43208 KEV NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused b… Patch first 9.8 critical 82.7% 2023-10-26
CVE-2014-1776 KEV Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of servic… Patch first 9.8 critical 82.7% 2014-04-27
CVE-2024-43468 KEV Microsoft Configuration Manager Remote Code Execution Vulnerability Patch first 9.8 critical 80.9% 2024-10-08
CVE-2020-10987 KEV The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceN… Patch first 9.8 critical 79.8% 2020-07-13
CVE-2023-49103 KEV An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.p… Patch first 10.0 critical 78.4% 2023-11-21
CVE-2021-28799 KEV An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allo… Patch first 10.0 critical 78.3% 2021-05-13
CVE-2022-26318 KEV On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS be… Patch first 9.8 critical 78.2% 2022-03-04
CVE-2026-16232 KEV An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicatio… Patch first 9.8 critical 78% 2026-07-22
CVE-2026-8037 KEV OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary comm… Patch first 9.6 critical 77.4% 2026-06-04
CVE-2023-34192 KEV Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the… Patch first 9.0 critical 77.3% 2023-07-06
CVE-2019-7238 KEV Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control. Patch first 9.8 critical 77.1% 2019-03-21
CVE-2026-25089 KEV A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.… Patch first 9.8 critical 76.1% 2026-06-09
CVE-2025-1316 KEV Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device Patch first 9.8 critical 74.5% 2025-03-05
CVE-2021-42258 KEV BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in… Patch first 9.8 critical 74.4% 2021-10-22
CVE-2018-14667 KEV The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated… Patch first 9.8 critical 74.2% 2018-11-06
CVE-2017-8543 KEV Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Wi… Patch first 9.8 critical 74.2% 2017-06-15
CVE-2019-1003029 KEV A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox… Patch first 9.9 critical 73.9% 2019-03-08
CVE-2025-6205 KEV A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access… Patch first 9.1 critical 73.3% 2025-08-04
CVE-2025-2746 KEV An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 u… Patch first 9.8 critical 73% 2025-03-24
CVE-2022-20699 KEV Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… Patch first 10.0 critical 72.5% 2022-02-10
CVE-2026-21962 KEV Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Pl… Patch first 10.0 critical 70.9% 2026-01-20
CVE-2025-20333 KEV A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FT… Patch first 9.9 critical 70.7% 2025-09-25
CVE-2020-4427 KEV IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with… Patch first 9.8 critical 70% 2020-05-07
CVE-2021-44026 KEV Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. Patch first 9.8 critical 69.9% 2021-11-19
← previous page 14 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt