peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,558 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

185,361 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-24858 KEV An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Forti… Patch first 9.8 critical 85.8% 2026-01-27
CVE-2021-30116 KEV Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page w… Patch first 10.0 critical 85.7% 2021-07-09
CVE-2023-27997 KEV A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6… Patch first 9.8 critical 85.7% 2023-06-13
CVE-2025-52691 KEV Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, pot… Patch first 10.0 critical 85.7% 2025-12-29
CVE-2022-27924 KEV Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These… Patch first 7.5 high 85.4% 2022-04-21
CVE-2023-24955 KEV Microsoft SharePoint Server Remote Code Execution Vulnerability Patch first 7.2 high 85.4% 2023-05-09
CVE-2021-1675 KEV Windows Print Spooler Remote Code Execution Vulnerability Patch first 7.8 high 85.3% 2021-06-08
CVE-2025-8110 KEV Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. Patch first 8.8 high 85.2% 2025-12-10
CVE-2023-41266 KEV A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier… Patch first 8.2 high 84.8% 2023-08-29
CVE-2019-10758 KEV mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to per… Patch first 9.9 critical 84.7% 2019-12-24
CVE-2024-28986 KEV SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an… Patch first 9.8 critical 84.6% 2024-08-13
CVE-2019-11581 KEV There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An… Patch first 9.8 critical 84.6% 2019-08-09
CVE-2025-64328 KEV FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore… Patch first 7.2 high 84.6% 2025-11-07
CVE-2020-28949 KEV Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to ov… Patch first 7.8 high 84.6% 2020-11-19
CVE-2020-15415 KEV On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell m… Patch first 9.8 critical 84.5% 2020-06-30
CVE-2020-7796 KEV Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. Patch first 9.8 critical 84.4% 2020-02-18
CVE-2020-12641 KEV rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for i… Patch first 9.8 critical 84.3% 2020-05-04
CVE-2024-38112 KEV Windows MSHTML Platform Spoofing Vulnerability Patch first 7.5 high 84.2% 2024-07-09
CVE-2025-40551 KEV SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whic… Patch first 9.8 critical 84.2% 2026-01-28
CVE-2021-21224 KEV Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pa… Patch first 8.8 high 84.2% 2021-04-26
CVE-2023-28432 KEV Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20… Patch first 7.5 high 84% 2023-03-22
CVE-2015-3035 KEV Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firm… Patch first 7.5 high 83.9% 2015-04-22
CVE-2019-9874 KEV Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allow… Patch first 9.8 critical 83.7% 2019-05-31
CVE-2019-0193 KEV In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the who… Patch first 7.2 high 83.5% 2019-08-01
CVE-2022-26923 KEV Active Directory Domain Services Elevation of Privilege Vulnerability Patch first 8.8 high 83.5% 2022-05-10
CVE-2024-21762 KEV A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through… Patch first 9.8 critical 83.4% 2024-02-09
CVE-2025-14847 KEV Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue af… Patch first 7.5 high 83.2% 2025-12-19
CVE-2019-7194 KEV This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP reco… Patch first 9.8 critical 83.1% 2019-12-05
CVE-2022-24990 KEV TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mob… Patch first 7.5 high 83% 2023-02-07
CVE-2020-3992 KEV OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-… Patch first 9.8 critical 83% 2020-10-20
← previous page 24 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt