peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,519 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

205,455 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-7238 KEV Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control. Patch first 9.8 critical 77.1% 2019-03-21
CVE-2020-13965 KEV An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is amo… Patch first 6.1 medium 76.6% 2020-06-09
CVE-2022-44698 KEV Windows SmartScreen Security Feature Bypass Vulnerability Patch first 5.4 medium 76.3% 2022-12-13
CVE-2026-25089 KEV A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.… Patch first 9.8 critical 76.1% 2026-06-09
CVE-2023-5631 KEV Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because o… Patch first 6.1 medium 75.9% 2023-10-18
CVE-2025-1316 KEV Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device Patch first 9.8 critical 74.5% 2025-03-05
CVE-2021-42258 KEV BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in… Patch first 9.8 critical 74.4% 2021-10-22
CVE-2018-14667 KEV The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated… Patch first 9.8 critical 74.2% 2018-11-06
CVE-2017-8543 KEV Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Wi… Patch first 9.8 critical 74.2% 2017-06-15
CVE-2019-1003029 KEV A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox… Patch first 9.9 critical 73.9% 2019-03-08
CVE-2025-6205 KEV A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access… Patch first 9.1 critical 73.3% 2025-08-04
CVE-2025-2746 KEV An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 u… Patch first 9.8 critical 73% 2025-03-24
CVE-2022-20699 KEV Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… Patch first 10.0 critical 72.5% 2022-02-10
CVE-2022-28810 KEV Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTE… Patch first 6.8 medium 71% 2022-04-18
CVE-2026-21962 KEV Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Pl… Patch first 10.0 critical 70.9% 2026-01-20
CVE-2025-20333 KEV A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FT… Patch first 9.9 critical 70.7% 2025-09-25
CVE-2020-4427 KEV IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with… Patch first 9.8 critical 70% 2020-05-07
CVE-2021-44026 KEV Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. Patch first 9.8 critical 69.9% 2021-11-19
CVE-2020-4430 KEV IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker co… Patch first 4.3 medium 68.5% 2020-05-07
CVE-2021-30657 KEV A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious… Patch first 5.5 medium 68.5% 2021-09-08
CVE-2025-59718 KEV A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 t… Patch first 9.8 critical 68.3% 2025-12-09
CVE-2023-28461 KEV Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gate… Patch first 9.8 critical 68.1% 2023-03-15
CVE-2025-20337 KEV A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the unde… Patch first 10.0 critical 67.8% 2025-07-16
CVE-2024-57726 KEV SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive perm… Patch first 9.9 critical 66.6% 2025-01-15
CVE-2025-31125 KEV Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicit… Patch first 5.3 medium 64.7% 2025-03-31
CVE-2025-2776 KEV SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functiona… Patch first 9.3 critical 64.4% 2025-05-07
CVE-2016-20017 KEV D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016… Patch first 9.8 critical 64.2% 2022-10-19
CVE-2023-43770 KEV Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/li… Patch first 6.1 medium 63.7% 2023-09-22
CVE-2015-4068 KEV Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of ser… Patch first 9.1 critical 63.6% 2015-05-29
CVE-2021-22681 KEV Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers ar… Patch first 9.8 critical 63.6% 2021-03-03
← previous page 16 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt