peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,519 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

317,898 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-49897 KEV An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vul… Patch first 8.8 high 50.4% 2023-12-06
CVE-2013-7331 KEV The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC s… Patch first 6.5 medium 50.2% 2014-02-26
CVE-2021-22017 KEV Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acces… Patch first 5.3 medium 49.2% 2021-09-23
CVE-2021-3493 KEV The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files i… Patch first 8.8 high 49.2% 2021-04-17
CVE-2023-37580 KEV Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. Patch first 6.1 medium 49.1% 2023-07-31
CVE-2023-5217 KEV Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exp… Patch first 8.8 high 49% 2023-09-28
CVE-2015-1671 KEV The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live… Patch first 7.8 high 49% 2015-05-13
CVE-2023-28252 KEV Windows Common Log File System Driver Elevation of Privilege Vulnerability Patch first 7.8 high 49% 2023-04-11
CVE-2026-85046 KEV Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML… Patch first 8.8 high 48.9% 2026-09-03
CVE-2025-68645 KEV A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling o… Patch first 8.8 high 48.9% 2025-12-22
CVE-2020-9715 KEV Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-a… Patch first 7.8 high 48.6% 2020-08-19
CVE-2020-16009 KEV Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a craf… Patch first 8.8 high 48.3% 2020-11-03
CVE-2016-1646 KEV The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider eleme… Patch first 8.8 high 48.1% 2016-03-29
CVE-2006-2492 KEV Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-ass… Patch first 8.8 high 48.1% 2006-05-20
CVE-2021-26829 KEV OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. Patch first 5.4 medium 48.1% 2021-06-11
CVE-2021-40407 KEV An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], base… Patch first 7.2 high 47.6% 2022-01-28
CVE-2014-4123 KEV Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privil… Patch first 8.8 high 47.1% 2014-10-15
CVE-2022-39197 KEV An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the C… Patch first 6.1 medium 46.4% 2022-09-22
CVE-2019-1579 KEV Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProt… Patch first 8.1 high 46.2% 2019-07-19
CVE-2024-43573 KEV Windows MSHTML Platform Spoofing Vulnerability Patch first 6.5 medium 46.1% 2024-10-08
CVE-2017-16651 KEV Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, in… Patch first 7.8 high 45.7% 2017-11-09
CVE-2017-6737 KEV A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely ex… Patch first 8.8 high 45.2% 2017-07-17
CVE-2024-29988 KEV SmartScreen Prompt Security Feature Bypass Vulnerability Patch first 8.8 high 44.9% 2024-04-09
CVE-2015-2425 KEV Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… Patch first 8.8 high 44.7% 2015-07-14
CVE-2013-3900 KEV Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and… Patch first 5.5 medium 44.6% 2013-12-11
CVE-2024-9379 KEV SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrar… Patch first 6.5 medium 43.8% 2024-10-08
CVE-2014-100005 KEV Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to h… Patch first 8.0 high 43.5% 2015-01-13
CVE-2023-36874 KEV Windows Error Reporting Service Elevation of Privilege Vulnerability Patch first 7.8 high 43.4% 2023-07-11
CVE-2007-0671 KEV Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attacke… Patch first 8.8 high 43.2% 2007-02-03
CVE-2009-0238 KEV Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, a… Patch first 8.8 high 43.2% 2009-02-25
← previous page 17 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt