peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,553 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

185,360 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-7399 KEV Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to wri… Patch first 8.8 high 91.9% 2024-08-12
CVE-2022-37042 KEV Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing auth… Patch first 9.8 critical 91.9% 2022-08-12
CVE-2021-42321 KEV Microsoft Exchange Server Remote Code Execution Vulnerability Patch first 8.8 high 91.7% 2021-11-10
CVE-2024-11680 KEV ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw… Patch first 9.8 critical 91.7% 2024-11-26
CVE-2022-26352 KEV An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose file… Patch first 9.8 critical 91.6% 2022-07-17
CVE-2026-20182 KEV May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed i… Patch first 10.0 critical 91.5% 2026-05-14
CVE-2026-85706 KEV GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 1… Patch first 10.0 critical 91.4% 2026-09-12
CVE-2025-9242 KEV An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code.… Patch first 9.8 critical 91.3% 2025-09-17
CVE-2024-13160 KEV Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthent… Patch first 9.8 critical 91.2% 2025-01-14
CVE-2021-35211 KEV Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If e… Patch first 9.0 critical 91.2% 2021-07-14
CVE-2026-1731 KEV BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code executi… Patch first 9.8 critical 91% 2026-02-06
CVE-2020-8243 KEV A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform a… Patch first 7.2 high 90.8% 2020-09-30
CVE-2017-12149 KEV In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFi… Patch first 9.8 critical 90.7% 2017-10-04
CVE-2021-21315 KEV The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,… Patch first 7.1 high 90.7% 2021-02-16
CVE-2025-6218 KEV RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… Patch first 7.8 high 90.5% 2025-06-21
CVE-2021-32648 KEV octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account… Patch first 8.2 high 90.4% 2021-08-26
CVE-2024-40711 KEV A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). Patch first 9.8 critical 90.4% 2024-09-07
CVE-2016-8735 KEV Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12… Patch first 9.8 critical 90.3% 2017-04-06
CVE-2021-20123 KEV A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. A… Patch first 7.5 high 90.2% 2021-10-13
CVE-2025-37164 KEV A remote code execution issue exists in HPE OneView. Patch first 10.0 critical 90.2% 2025-12-16
CVE-2020-29583 KEV Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can b… Patch first 9.8 critical 90.2% 2020-12-22
CVE-2023-40044 KEV In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Tra… Patch first 10.0 critical 90.2% 2023-09-27
CVE-2024-13161 KEV Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthent… Patch first 9.8 critical 90.1% 2025-01-14
CVE-2020-17463 KEV FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. Patch first 9.8 critical 89.7% 2020-08-13
CVE-2019-7195 KEV This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP reco… Patch first 9.8 critical 89.7% 2019-12-05
CVE-2023-20273 KEV A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of… Patch first 7.2 high 89.6% 2023-10-25
CVE-2019-17621 KEV The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system… Patch first 9.8 critical 89.6% 2019-12-30
CVE-2025-26399 KEV SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if expl… Patch first 9.8 critical 89.5% 2025-09-23
CVE-2018-14839 KEV LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with pa… Patch first 9.8 critical 89.4% 2019-05-14
CVE-2021-20021 KEV A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP requ… Patch first 9.8 critical 88.7% 2021-04-09
← previous page 22 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt