peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,529 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

205,458 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-8196 KEV Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWA… Patch first 4.3 medium 26.3% 2020-07-10
CVE-2016-3351 KEV Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Micros… Patch first 6.5 medium 26.3% 2016-09-14
CVE-2015-2590 KEV Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality… Patch first 9.8 critical 25.5% 2015-07-16
CVE-2023-20269 KEV A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software… Patch first 5.0 medium 25.5% 2023-09-06
CVE-2026-20122 KEV A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local fi… Patch first 5.4 medium 25% 2026-02-25
CVE-2025-4632 KEV Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to wri… Patch first 9.8 critical 24.3% 2025-05-13
CVE-2016-9563 KEV BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him… Patch first 6.5 medium 24.2% 2016-11-23
CVE-2026-60004 KEV Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. Patch first 9.8 critical 24% 2026-08-26
CVE-2024-27443 KEV An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of… Patch first 6.1 medium 23.6% 2024-08-12
CVE-2025-23006 KEV Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central M… Patch first 9.8 critical 23.4% 2025-01-23
CVE-2024-9680 KEV An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of th… Patch first 9.8 critical 23.2% 2024-10-09
CVE-2024-44309 KEV A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1… Patch first 6.3 medium 22.6% 2024-11-20
CVE-2024-37079 KEV vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter S… Patch first 9.8 critical 22.4% 2024-06-18
CVE-2014-0546 KEV Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and conseque… Patch first 9.8 critical 22.3% 2014-08-12
CVE-2016-1019 KEV Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code… Patch first 9.8 critical 22.3% 2016-04-07
CVE-2025-54948 KEV A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and e… Patch first 9.4 critical 22% 2025-08-05
CVE-2016-0162 KEV Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explor… Patch first 4.3 medium 22% 2016-04-12
CVE-2025-43300 KEV An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS… Patch first 10.0 critical 22% 2025-08-21
CVE-2024-7971 KEV Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium s… Patch first 9.6 critical 21.1% 2024-08-21
CVE-2023-36563 KEV Microsoft WordPad Information Disclosure Vulnerability Patch first 6.5 medium 20.7% 2023-10-10
CVE-2026-48939 KEV A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP… Patch first 9.8 critical 20.1% 2026-06-20
CVE-2016-4171 KEV Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as explo… Patch first 9.8 critical 20.1% 2016-06-16
CVE-2021-37976 KEV Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information fr… Patch first 6.5 medium 19.9% 2021-10-08
CVE-2026-93616 KEV A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Manageme… Patch first 9.8 critical 19.7% 2026-09-22
CVE-2025-7775 KEV Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is confi… Patch first 9.8 critical 19.6% 2025-08-26
CVE-2023-36761 KEV Microsoft Word Information Disclosure Vulnerability Patch first 6.5 medium 19.6% 2023-09-12
CVE-2022-26871 KEV An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which co… Patch first 9.8 critical 19.5% 2022-03-29
CVE-2021-41379 KEV Windows Installer Elevation of Privilege Vulnerability Patch first 5.5 medium 19.5% 2021-11-10
CVE-2024-20359 KEV A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Secur… Patch first 6.0 medium 19.4% 2024-04-24
CVE-2025-67038 KEV An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. T… Patch first 9.8 critical 19.3% 2026-03-11
← previous page 20 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt