peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,528 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

185,355 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-24086 KEV Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checko… Patch first 9.8 critical 99.2% 2022-02-16
CVE-2023-22515 KEV Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerab… Patch first 9.8 critical 99.2% 2023-10-04
CVE-2022-30333 KEV RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by c… Patch first 7.5 high 99.1% 2022-05-09
CVE-2025-68613 KEV n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remot… Patch first 9.9 critical 99% 2025-12-19
CVE-2021-40539 KEV Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. Patch first 9.8 critical 99% 2021-09-07
CVE-2023-36884 KEV Windows Search Remote Code Execution Vulnerability Patch first 7.5 high 98.9% 2023-07-11
CVE-2022-3236 KEV A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older… Patch first 9.8 critical 98.9% 2022-09-23
CVE-2023-47246 KEV In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as… Patch first 9.8 critical 98.9% 2023-11-10
CVE-2025-32433 KEV Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may… Patch first 10.0 critical 98.8% 2025-04-16
CVE-2026-1281 KEV A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Patch first 9.8 critical 98.7% 2026-01-29
CVE-2022-27925 KEV Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated us… Patch first 7.2 high 98.7% 2022-04-21
CVE-2026-1340 KEV A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Patch first 9.8 critical 98.6% 2026-01-29
CVE-2024-29059 KEV .NET Framework Information Disclosure Vulnerability Patch first 7.5 high 98.6% 2024-03-23
CVE-2024-50623 KEV In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could l… Patch first 9.8 critical 98.6% 2024-10-28
CVE-2024-8963 KEV Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. Patch first 9.4 critical 98.6% 2024-09-19
CVE-2024-9463 KEV An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expe… Patch first 7.5 high 98.5% 2024-10-09
CVE-2024-50603 KEV An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used… Patch first 10.0 critical 98.5% 2025-01-08
CVE-2021-21311 KEV Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forg… Patch first 7.2 high 98.5% 2021-02-11
CVE-2025-0108 KEV An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web inter… Patch first 9.1 critical 98.5% 2025-02-12
CVE-2023-48788 KEV A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiCl… Patch first 9.8 critical 98.4% 2024-03-12
CVE-2022-21587 KEV Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are af… Patch first 9.8 critical 98.3% 2022-10-18
CVE-2018-1000861 KEV A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main… Patch first 9.8 critical 98.3% 2018-12-10
CVE-2023-20887 KEV Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks… Patch first 9.8 critical 98.3% 2023-06-07
CVE-2022-26138 KEV The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with… Patch first 9.8 critical 98.2% 2022-07-20
CVE-2021-33766 KEV Microsoft Exchange Server Information Disclosure Vulnerability Patch first 7.3 high 98.1% 2021-07-14
CVE-2020-6207 KEV SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service… Patch first 9.8 critical 98.1% 2020-03-10
CVE-2021-39144 KEV XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffic… Patch first 8.5 high 98.1% 2021-08-23
CVE-2024-41713 KEV A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated atta… Patch first 9.1 critical 98.1% 2024-10-21
CVE-2024-12987 KEV A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /… Patch first 7.3 high 98.1% 2024-12-27
CVE-2023-25717 KEV Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_use… Patch first 9.8 critical 98.1% 2023-02-13
← previous page 18 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt