peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,529 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

148,901 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-21513 KEV Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. Patch first 8.8 high 15.6% 2026-02-10
CVE-2023-35311 KEV Microsoft Outlook Security Feature Bypass Vulnerability Patch first 8.8 high 15.5% 2023-07-11
CVE-2026-34197 KEV Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache… Patch first 8.8 high 15.5% 2026-04-07
CVE-2015-0310 KEV Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly re… Patch first 7.8 high 15.1% 2015-01-23
CVE-2022-38028 KEV Windows Print Spooler Elevation of Privilege Vulnerability Patch first 7.8 high 14.9% 2022-10-11
CVE-2015-2360 KEV win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows… Patch first 8.8 high 14.8% 2015-06-10
CVE-2021-30883 KEV A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS… Patch first 7.8 high 14.7% 2021-08-24
CVE-2024-8069 KEV Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user o… Patch first 8.0 high 14.6% 2024-11-12
CVE-2026-18577 KEV An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 Patch first 8.1 high 14.6% 2026-08-02
CVE-2022-26485 KEV Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this… Patch first 8.8 high 14.3% 2022-12-22
CVE-2024-49039 KEV Windows Task Scheduler Elevation of Privilege Vulnerability Patch first 8.8 high 14.2% 2024-11-12
CVE-2021-22900 KEV A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to per… Patch first 7.2 high 14.1% 2021-05-27
CVE-2023-38180 KEV .NET and Visual Studio Denial of Service Vulnerability Patch first 7.5 high 14% 2023-08-08
CVE-2021-1789 KEV A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Secur… Patch first 8.8 high 14% 2021-04-02
CVE-2025-29824 KEV Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 13.9% 2025-04-08
CVE-2019-9875 KEV Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sendin… Patch first 8.8 high 13.8% 2019-05-31
CVE-2022-1364 KEV Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted… Patch first 8.8 high 13.7% 2022-07-26
CVE-2022-38181 KEV The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p… Patch first 8.8 high 13.6% 2022-10-25
CVE-2021-27876 KEV An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which… Patch first 8.1 high 13.5% 2021-03-01
CVE-2021-30858 KEV A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing… Patch first 8.8 high 13.4% 2021-08-24
CVE-2026-42271 KEV LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used… Patch first 8.8 high 12.8% 2026-05-08
CVE-2025-6554 KEV Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chrom… Patch first 8.1 high 12.6% 2025-06-30
CVE-2022-22675 KEV An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS M… Patch first 7.8 high 12.5% 2022-05-26
CVE-2022-20775 KEV A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is… Patch first 7.8 high 12.5% 2022-09-30
CVE-2023-36424 KEV Windows Common Log File System Driver Elevation of Privilege Vulnerability Patch first 7.8 high 12.2% 2023-11-14
CVE-2023-32373 KEV A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 an… Patch first 8.8 high 12.2% 2023-06-23
CVE-2021-28663 KEV The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-af… Patch first 8.8 high 12.1% 2021-05-10
CVE-2023-21715 KEV Microsoft Publisher Security Feature Bypass Vulnerability Patch first 7.3 high 12% 2023-02-14
CVE-2023-36033 KEV Windows DWM Core Library Elevation of Privilege Vulnerability Patch first 7.8 high 12% 2023-11-14
CVE-2017-11292 KEV Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the… Patch first 8.8 high 11.9% 2017-10-22
← previous page 20 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt