peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,519 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

398,519 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-12987 KEV A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /… Patch first 7.3 high 98.1% 2024-12-27
CVE-2023-25717 KEV Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_use… Patch first 9.8 critical 98.1% 2023-02-13
CVE-2024-3272 KEV ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-3… Patch first 9.8 critical 98% 2024-04-04
CVE-2021-35395 KEV Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access po… Patch first 9.8 critical 98% 2021-08-16
CVE-2018-19410 KEV PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator).… Patch first 9.8 critical 97.9% 2018-11-21
CVE-2020-14883 KEV Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.… Patch first 7.2 high 97.9% 2020-10-21
CVE-2023-25280 KEV OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_ad… Patch first 9.8 critical 97.9% 2023-03-16
CVE-2021-45382 KEV A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L route… Patch first 9.8 critical 97.8% 2022-02-17
CVE-2021-36380 KEV Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi. Patch first 9.8 critical 97.6% 2021-08-13
CVE-2025-20281 KEV A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the unde… Patch first 10.0 critical 97.6% 2025-06-25
CVE-2021-42237 KEV Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote… Patch first 9.8 critical 97.6% 2021-11-05
CVE-2025-34028 KEV The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expande… Patch first 10.0 critical 97.6% 2025-04-22
CVE-2020-25078 KEV An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint all… Patch first 7.5 high 97.5% 2020-09-02
CVE-2021-40444 KEV Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted a… Patch first 8.8 high 97.5% 2021-09-15
CVE-2024-56145 KEV Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this… Patch first 9.8 critical 97.4% 2024-12-18
CVE-2023-24489 KEV A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated att… Patch first 9.8 critical 97.3% 2023-07-10
CVE-2023-26360 KEV Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that c… Patch first 8.6 high 97.3% 2023-03-23
CVE-2020-1956 KEV Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is l… Patch first 8.8 high 97.3% 2020-05-22
CVE-2019-5544 KEV OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Criti… Patch first 9.8 critical 97.3% 2019-12-06
CVE-2021-41277 KEV Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->set… Patch first 10.0 critical 97.2% 2021-11-17
CVE-2025-2747 KEV An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for t… Patch first 9.8 critical 97.2% 2025-03-24
CVE-2023-23397 KEV Microsoft Outlook Elevation of Privilege Vulnerability Patch first 9.8 critical 97.2% 2023-03-14
CVE-2024-20439 KEV A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a stat… Patch first 9.8 critical 97.1% 2024-09-04
CVE-2023-38203 KEV Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vul… Patch first 9.8 critical 97.1% 2023-07-20
CVE-2025-54068 KEV Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve… Patch first 9.8 critical 97.1% 2025-07-17
CVE-2018-1273 KEV Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused b… Patch first 9.8 critical 97% 2018-04-11
CVE-2026-20253 KEV In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through… Patch first 9.8 critical 96.9% 2026-06-10
CVE-2023-52163 KEV Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer s… Patch first 8.8 high 96.9% 2025-02-03
CVE-2025-5086 KEV A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution… Patch first 9.0 critical 96.9% 2025-06-02
CVE-2020-25223 KEV A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11 Patch first 9.8 critical 96.8% 2020-09-25
← previous page 20 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt