peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,553 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

317,918 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-6742 KEV A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely ex… Patch first 8.8 high 21.4% 2017-07-17
CVE-2020-9377 KEV D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no… Patch first 8.8 high 21.3% 2020-07-09
CVE-2009-1862 KEV Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, all… Patch first 7.8 high 21.2% 2009-07-23
CVE-2012-5054 KEV Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitr… Patch first 8.8 high 21.2% 2012-09-24
CVE-2012-1854 KEV Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Appl… Patch first 7.8 high 21% 2012-07-10
CVE-2014-9163 KEV Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on… Patch first 7.8 high 20.7% 2014-12-10
CVE-2023-36563 KEV Microsoft WordPad Information Disclosure Vulnerability Patch first 6.5 medium 20.7% 2023-10-10
CVE-2024-40890 KEV **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmwa… Patch first 8.8 high 20.7% 2025-02-04
CVE-2014-8439 KEV Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0… Patch first 8.8 high 20.4% 2014-11-25
CVE-2021-21148 KEV Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML… Patch first 8.8 high 20% 2021-02-09
CVE-2021-37976 KEV Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information fr… Patch first 6.5 medium 19.9% 2021-10-08
CVE-2023-36761 KEV Microsoft Word Information Disclosure Vulnerability Patch first 6.5 medium 19.6% 2023-09-12
CVE-2025-66376 KEV Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives… Patch first 7.2 high 19.6% 2026-01-05
CVE-2021-41379 KEV Windows Installer Elevation of Privilege Vulnerability Patch first 5.5 medium 19.5% 2021-11-10
CVE-2024-20359 KEV A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Secur… Patch first 6.0 medium 19.4% 2024-04-24
CVE-2016-1010 KEV Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux,… Patch first 8.8 high 19.3% 2016-03-12
CVE-2023-7101 KEV Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code executi… Patch first 7.8 high 19.1% 2023-12-24
CVE-2023-37450 KEV The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9… Patch first 8.8 high 19% 2023-07-27
CVE-2016-7892 KEV Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class.… Patch first 8.8 high 18.8% 2016-12-15
CVE-2014-2120 KEV Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to injec… Patch first 6.1 medium 18.8% 2014-03-19
CVE-2022-22047 KEV Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability Patch first 7.8 high 18.8% 2022-07-12
CVE-2020-11899 KEV The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. Patch first 5.4 medium 18.6% 2020-06-17
CVE-2024-7965 KEV Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a craf… Patch first 8.8 high 18.5% 2024-08-21
CVE-2022-22718 KEV Windows Print Spooler Elevation of Privilege Vulnerability Patch first 7.8 high 18.5% 2022-02-09
CVE-2019-5591 KEV A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impers… Patch first 6.5 medium 18.4% 2020-08-14
CVE-2018-8440 KEV An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevat… Patch first 7.8 high 18.4% 2018-09-13
CVE-2026-87902 KEV An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active the… Patch first 8.1 high 18.2% 2026-09-22
CVE-2017-0022 KEV Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1… Patch first 6.5 medium 18.1% 2017-03-17
CVE-2023-42916 KEV An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 1… Patch first 6.5 medium 17.8% 2023-11-30
CVE-2026-22719 KEV VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary comma… Patch first 8.1 high 17.7% 2026-02-25
← previous page 22 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt