peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,553 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

205,466 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-64849 KEV MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated… Patch first 9.3 critical 9.8% 2026-08-17
CVE-2026-63077 KEV In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol Patch first 9.8 critical 9.8% 2026-07-27
CVE-2022-20701 KEV Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… Patch first 10.0 critical 9.7% 2022-02-10
CVE-2019-0703 KEV An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosur… Patch first 6.5 medium 9.6% 2019-04-09
CVE-2026-35273 KEV Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions th… Patch first 9.8 critical 9.4% 2026-06-11
CVE-2022-20703 KEV Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… Patch first 10.0 critical 9.2% 2022-02-10
CVE-2026-35616 KEV A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized c… Patch first 9.8 critical 9.1% 2026-04-04
CVE-2026-83548 KEV A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unau… Patch first 10.0 critical 8.8% 2026-09-01
CVE-2018-14558 KEV An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9),… Patch first 9.8 critical 8.7% 2018-10-30
CVE-2024-4671 KEV Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially p… Patch first 9.6 critical 8.3% 2024-05-14
CVE-2019-0676 KEV An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this… Patch first 6.5 medium 8.1% 2019-03-05
CVE-2019-11634 KEV Citrix Workspace App before 1904 for Windows has Incorrect Access Control. Patch first 9.8 critical 8% 2019-05-22
CVE-2018-19323 KEV The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GUR… Patch first 9.8 critical 7.8% 2018-12-21
CVE-2012-1710 KEV Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect c… Patch first 9.8 critical 7.8% 2012-05-03
CVE-2021-1870 KEV A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update… Patch first 9.8 critical 7.7% 2021-04-02
CVE-2024-5274 KEV Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML… Patch first 9.6 critical 7.5% 2024-05-28
CVE-2020-1040 KEV A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user o… Patch first 9.0 critical 7.4% 2020-07-14
CVE-2026-20805 KEV Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. Patch first 5.5 medium 7.2% 2026-01-13
CVE-2021-1879 KEV This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. P… Patch first 6.1 medium 7.1% 2021-04-02
CVE-2019-0344 KEV Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to exe… Patch first 9.8 critical 7.1% 2019-08-14
CVE-2026-48710 KEV Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to recon… Patch first 6.5 medium 7.1% 2026-05-26
CVE-2026-19490 KEV Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1… Patch first 9.8 critical 7% 2026-08-19
CVE-2021-1871 KEV A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update… Patch first 9.8 critical 7% 2021-04-02
CVE-2026-15409 KEV A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacke… Patch first 10.0 critical 6.8% 2026-07-14
CVE-2013-1675 KEV Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initial… Patch first 6.5 medium 6.7% 2013-05-16
CVE-2022-27518 KEV Unauthenticated remote arbitrary code execution Patch first 9.8 critical 6.7% 2022-12-13
CVE-2021-22600 KEV A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or d… Patch first 6.6 medium 6.5% 2022-01-26
CVE-2012-0767 KEV Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris… Patch first 6.1 medium 6.4% 2012-02-16
CVE-2020-16010 KEV Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to po… Patch first 9.6 critical 6.4% 2020-11-03
CVE-2026-50751 KEV A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote atta… Patch first 9.3 critical 6.3% 2026-06-08
← previous page 23 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt