peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-26

185,314 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-3452 KEV EXP A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co… Patch first 7.5 high 100% 2020-07-22
CVE-2018-7600 KEV EXP Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue… Patch first 9.8 critical 100% 2018-03-29
CVE-2018-11776 KEV EXP Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by us… Patch first 8.1 high 100% 2018-08-22
CVE-2017-10271 KEV EXP Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected a… Patch first 7.5 high 100% 2017-10-19
CVE-2023-42793 KEV EXP In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible Patch first 9.8 critical 100% 2023-09-19
CVE-2024-4577 KEV EXP In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use… Patch first 9.8 critical 100% 2024-06-09
CVE-2019-9670 KEV EXP mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstra… Patch first 9.8 critical 100% 2019-05-29
CVE-2022-40684 KEV EXP An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiPr… Patch first 9.8 critical 100% 2022-10-18
CVE-2025-0282 KEV EXP A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for Z… Patch first 9.0 critical 100% 2025-01-08
CVE-2024-4879 KEV EXP ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerabilit… Patch first 9.8 critical 100% 2024-07-10
CVE-2025-31161 KEV EXP CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is use… Patch first 9.8 critical 100% 2025-04-03
CVE-2012-0158 KEV EXP The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3,… Patch first 8.8 high 100% 2012-04-10
CVE-2014-8361 KEV EXP The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the… Patch first 9.8 critical 100% 2015-05-01
CVE-2025-5777 KEV EXP Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy… Patch first 7.5 high 100% 2025-06-17
CVE-2022-47986 KEV EXP IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserializat… Patch first 9.8 critical 100% 2023-02-17
CVE-2017-12617 KEV EXP When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setti… Patch first 8.1 high 100% 2017-10-04
CVE-2021-42013 KEV EXP It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs… Patch first 9.8 critical 100% 2021-10-07
CVE-2019-2725 KEV EXP Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected a… Patch first 9.8 critical 100% 2019-04-26
CVE-2020-0688 KEV EXP A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microso… Patch first 8.8 high 100% 2020-02-11
CVE-2021-3156 KEV EXP Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoe… Patch first 7.8 high 100% 2021-01-26
CVE-2019-10149 KEV EXP A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c m… Patch first 9.8 critical 100% 2019-06-05
CVE-2018-2628 KEV EXP Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… Patch first 9.8 critical 100% 2018-04-19
CVE-2022-1388 KEV EXP On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5,… Patch first 9.8 critical 100% 2022-05-05
CVE-2018-15961 KEV EXP Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerab… Patch first 9.8 critical 100% 2018-09-25
CVE-2018-10562 KEV EXP An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponFor… Patch first 9.8 critical 99.9% 2018-05-04
CVE-2017-11882 KEV EXP Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an a… Patch first 7.8 high 99.9% 2017-11-15
CVE-2015-3113 KEV EXP Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468… Patch first 9.8 critical 99.9% 2015-06-23
CVE-2022-30525 KEV EXP A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware ve… Patch first 9.8 critical 99.9% 2022-05-12
CVE-2021-3129 KEV EXP Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure us… Patch first 9.8 critical 99.9% 2021-01-12
CVE-2020-10189 KEV EXP Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the Fi… Patch first 9.8 critical 99.9% 2020-03-06
← previous page 2 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt