peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,528 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

36,454 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-10585 KEV Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… Patch first 9.8 critical 5.4% 2025-09-24
CVE-2019-16256 KEV Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location an… Patch first 9.8 critical 4.9% 2019-09-12
CVE-2020-29574 KEV An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements… Patch first 9.8 critical 4.7% 2020-12-11
CVE-2026-81578 KEV An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthentic… Patch first 9.8 critical 4.5% 2026-08-28
CVE-2020-2021 KEV When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecke… Patch first 10.0 critical 4.4% 2020-06-29
CVE-2022-26501 KEV Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). Patch first 9.8 critical 4.1% 2022-03-17
CVE-2026-3055 KEV Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread Patch first 9.8 critical 4% 2026-03-23
CVE-2026-75650 KEV Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary co… Patch first 10.0 critical 3.9% 2026-09-07
CVE-2026-82078 KEV An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates… Patch first 9.1 critical 3.8% 2026-08-28
CVE-2024-9537 KEV ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vuln… Patch first 9.8 critical 3.8% 2024-10-18
CVE-2025-24201 KEV An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and… Patch first 10.0 critical 3.8% 2025-03-11
CVE-2025-42599 KEV Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request create… Patch first 9.8 critical 3.3% 2025-04-18
CVE-2026-50522 KEV Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Patch first 9.8 critical 3% 2026-07-14
CVE-2025-39682 KEV In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must… Patch first 9.8 critical 2.9% 2025-09-05
CVE-2025-61932 KEV Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing a… Patch first 9.8 critical 2.8% 2025-10-20
CVE-2020-16017 KEV Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potenti… Patch first 9.6 critical 2.7% 2021-01-08
CVE-2022-42948 KEV Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to… Patch first 9.8 critical 2.7% 2023-03-24
CVE-2023-29492 KEV Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not prov… Patch first 9.8 critical 2.7% 2023-04-11
CVE-2026-59310 KEV VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this is… Patch first 9.8 critical 2.6% 2026-07-30
CVE-2025-32975 KEV Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5),… Patch first 10.0 critical 2.5% 2025-06-24
CVE-2022-26486 KEV An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the… Patch first 9.6 critical 2.3% 2022-12-22
CVE-2025-53521 KEV When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Softwa… Patch first 9.8 critical 2.3% 2025-10-15
CVE-2026-94127 KEV When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution… Patch first 9.8 critical 2.2% 2026-09-22
CVE-2026-49869 KEV Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().e… Patch first 10.0 critical 2.1% 2026-06-26
CVE-2026-45247 KEV Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attacke… Patch first 9.8 critical 2.1% 2026-05-26
CVE-2023-6448 KEV Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacke… Patch first 9.8 critical 2.1% 2023-12-05
CVE-2026-86060 KEV RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted… Patch first 9.8 critical 1.8% 2026-09-05
CVE-2026-34909 KEV A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying… Patch first 10.0 critical 1.8% 2026-05-22
CVE-2026-72530 KEV A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, a… Patch first 9.0 critical 1.7% 2026-08-19
CVE-2026-33824 KEV Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. Patch first 9.8 critical 1.6% 2026-04-14
← previous page 20 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt