peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,553 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

185,360 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-61757 KEV Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.… Patch first 9.8 critical 88.6% 2025-10-21
CVE-2024-8190 KEV An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to o… Patch first 7.2 high 88.5% 2024-09-10
CVE-2026-48908 KEV A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution… Patch first 9.8 critical 88.5% 2026-06-20
CVE-2026-20127 KEV A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-… Patch first 10.0 critical 88.5% 2026-02-25
CVE-2023-41265 KEV An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 an… Patch first 9.6 critical 88.2% 2023-08-29
CVE-2026-20230 KEV A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM S… Patch first 8.6 high 88.2% 2026-06-03
CVE-2026-20079 KEV A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypa… Patch first 10.0 critical 88.2% 2026-03-04
CVE-2026-24423 KEV SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. T… Patch first 9.8 critical 88.2% 2026-01-23
CVE-2019-7192 KEV This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recom… Patch first 9.8 critical 88.1% 2019-12-05
CVE-2023-36025 KEV Windows SmartScreen Security Feature Bypass Vulnerability Patch first 8.8 high 88.1% 2023-11-14
CVE-2025-54253 KEV Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. A… Patch first 10.0 critical 88% 2025-08-05
CVE-2025-29635 KEV A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices b… Patch first 7.2 high 87.9% 2025-03-25
CVE-2022-27593 KEV An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could al… Patch first 10.0 critical 87.9% 2022-09-08
CVE-2024-58136 KEV Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild… Patch first 9.0 critical 87.8% 2025-04-10
CVE-2020-17496 KEV vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.… Patch first 9.8 critical 87.7% 2020-08-12
CVE-2012-0151 KEV The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008… Patch first 7.8 high 87.7% 2012-04-10
CVE-2023-2868 KEV A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.… Patch first 9.4 critical 87.7% 2023-05-24
CVE-2026-1603 KEV An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credentia… Patch first 8.6 high 87.6% 2026-02-10
CVE-2026-71362 KEV Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vuln… Patch first 9.1 critical 87.5% 2026-08-11
CVE-2022-26143 KEV The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain se… Patch first 9.8 critical 87.3% 2022-03-10
CVE-2024-12356 KEV A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated att… Patch first 9.8 critical 87.3% 2024-12-17
CVE-2025-33053 KEV External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. Patch first 8.8 high 87% 2025-06-10
CVE-2021-31755 KEV An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows at… Patch first 9.8 critical 86.9% 2021-05-07
CVE-2017-18362 KEV ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to th… Patch first 9.8 critical 86.8% 2019-02-05
CVE-2021-40655 KEV An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a pos… Patch first 7.5 high 86.7% 2021-09-24
CVE-2024-51567 KEV upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute a… Patch first 10.0 critical 86.6% 2024-10-29
CVE-2025-4428 KEV Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to… Patch first 7.2 high 86.5% 2025-05-13
CVE-2019-16057 KEV The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection. Patch first 9.8 critical 86.5% 2019-09-16
CVE-2021-21017 KEV Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap… Patch first 8.8 high 86.3% 2021-02-11
CVE-2015-2545 KEV Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microso… Patch first 7.8 high 85.9% 2015-09-09
← previous page 23 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt