peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,529 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

317,905 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-41128 KEV Windows Scripting Languages Remote Code Execution Vulnerability Patch first 8.8 high 24.6% 2022-11-09
CVE-2023-41993 KEV The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. App… Patch first 8.8 high 24.3% 2023-09-21
CVE-2026-21510 KEV Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. Patch first 8.8 high 24.2% 2026-02-10
CVE-2016-9563 KEV BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him… Patch first 6.5 medium 24.2% 2016-11-23
CVE-2022-1096 KEV Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Patch first 8.8 high 24.2% 2022-07-23
CVE-2020-1380 KEV A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability co… Patch first 7.8 high 24.2% 2020-08-17
CVE-2021-21166 KEV Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Patch first 8.8 high 24% 2021-03-09
CVE-2023-32439 KEV A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ve… Patch first 8.8 high 24% 2023-06-23
CVE-2021-27878 KEV An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which… Patch first 8.8 high 24% 2021-03-01
CVE-2024-27443 KEV An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of… Patch first 6.1 medium 23.6% 2024-08-12
CVE-2021-36948 KEV Windows Update Medic Service Elevation of Privilege Vulnerability Patch first 7.8 high 23.3% 2021-08-12
CVE-2023-28206 KEV An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1,… Patch first 8.6 high 23.2% 2023-04-10
CVE-2015-5317 KEV The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information… Patch first 7.5 high 23% 2015-11-25
CVE-2023-32435 KEV A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16… Patch first 8.8 high 23% 2023-06-23
CVE-2022-0609 KEV Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM… Patch first 8.8 high 22.9% 2022-04-05
CVE-2021-22899 KEV A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code executi… Patch first 8.8 high 22.9% 2021-05-27
CVE-2024-44309 KEV A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1… Patch first 6.3 medium 22.6% 2024-11-20
CVE-2017-0210 KEV An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker t… Patch first 8.8 high 22.3% 2017-04-12
CVE-2025-14174 KEV Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access… Patch first 8.8 high 22.3% 2025-12-12
CVE-2021-31956 KEV Windows NTFS Elevation of Privilege Vulnerability Patch first 7.8 high 22.3% 2021-06-08
CVE-2018-8639 KEV An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation… Patch first 7.8 high 22.2% 2018-12-12
CVE-2016-0162 KEV Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explor… Patch first 4.3 medium 22% 2016-04-12
CVE-2020-27930 KEV A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS… Patch first 7.8 high 22% 2020-12-08
CVE-2021-34484 KEV Windows User Profile Service Elevation of Privilege Vulnerability Patch first 7.8 high 21.8% 2021-08-12
CVE-2019-1297 KEV A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft… Patch first 8.8 high 21.8% 2019-09-11
CVE-2025-23209 KEV Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerabi… Patch first 8.0 high 21.8% 2025-01-18
CVE-2019-0903 KEV A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remo… Patch first 8.8 high 21.7% 2019-05-16
CVE-2023-29360 KEV Microsoft Streaming Service Elevation of Privilege Vulnerability Patch first 8.4 high 21.6% 2023-06-14
CVE-2024-40891 KEV **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10… Patch first 8.8 high 21.5% 2025-02-04
CVE-2018-19943 KEV If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in th… Patch first 8.0 high 21.5% 2020-10-28
← previous page 21 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt