peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,424 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-26

168,968 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-49706 KEV Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Patch first 6.5 medium 99.1% 2025-07-08
CVE-2023-36846 KEV A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attac… Patch first 5.3 medium 93.5% 2023-08-17
CVE-2023-41763 KEV Skype for Business Elevation of Privilege Vulnerability Patch first 5.3 medium 90.4% 2023-10-10
CVE-2023-36844 KEV A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacke… Patch first 5.3 medium 90% 2023-08-17
CVE-2020-8193 KEV Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWA… Patch first 6.5 medium 88.4% 2020-07-10
CVE-2021-21973 KEV The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin.… Patch first 5.3 medium 87.6% 2021-02-24
CVE-2025-20362 KEV Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software… Patch first 6.5 medium 87.1% 2025-09-25
CVE-2020-3580 KEV Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) So… Patch first 6.1 medium 85.6% 2020-10-21
CVE-2024-43451 KEV NTLM Hash Disclosure Spoofing Vulnerability Patch first 6.5 medium 84.1% 2024-11-12
CVE-2023-36847 KEV A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attack… Patch first 5.3 medium 83.5% 2023-08-17
CVE-2024-0769 KEV ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unk… Patch first 5.3 medium 82.7% 2024-01-21
CVE-2021-31955 KEV Windows Kernel Information Disclosure Vulnerability Patch first 5.5 medium 81.1% 2021-06-08
CVE-2018-18809 KEV The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperRep… Patch first 6.5 medium 79.1% 2019-03-07
CVE-2023-24880 KEV Windows SmartScreen Security Feature Bypass Vulnerability Patch first 4.4 medium 78% 2023-03-14
CVE-2020-13965 KEV An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is amo… Patch first 6.1 medium 76.6% 2020-06-09
CVE-2022-44698 KEV Windows SmartScreen Security Feature Bypass Vulnerability Patch first 5.4 medium 76.3% 2022-12-13
CVE-2023-5631 KEV Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because o… Patch first 6.1 medium 75.9% 2023-10-18
CVE-2022-28810 KEV Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTE… Patch first 6.8 medium 71% 2022-04-18
CVE-2020-4430 KEV IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker co… Patch first 4.3 medium 68.5% 2020-05-07
CVE-2021-30657 KEV A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious… Patch first 5.5 medium 68.5% 2021-09-08
CVE-2025-31125 KEV Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicit… Patch first 5.3 medium 64.7% 2025-03-31
CVE-2023-43770 KEV Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/li… Patch first 6.1 medium 63.7% 2023-09-22
CVE-2025-47813 KEV loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. Patch first 4.3 medium 63% 2025-07-10
CVE-2025-25181 KEV A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands v… Patch first 5.8 medium 57.3% 2025-02-03
CVE-2023-20118 KEV A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allo… Patch first 6.5 medium 54.1% 2023-04-13
CVE-2021-22175 KEV When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting… Patch first 6.8 medium 53.4% 2021-06-11
CVE-2021-20023 KEV SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote h… Patch first 4.9 medium 51.4% 2021-04-20
CVE-2013-7331 KEV The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC s… Patch first 6.5 medium 50.2% 2014-02-26
CVE-2021-22017 KEV Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acces… Patch first 5.3 medium 49.2% 2021-09-23
CVE-2023-37580 KEV Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. Patch first 6.1 medium 49.1% 2023-07-31
← previous page 2 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt