peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,553 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

148,906 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-0167 KEV The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2… Patch first 7.8 high 5.7% 2016-04-12
CVE-2010-3035 KEV Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to c… Patch first 7.5 high 5.7% 2010-08-30
CVE-2024-30051 KEV Windows DWM Core Library Elevation of Privilege Vulnerability Patch first 7.8 high 5.6% 2024-05-14
CVE-2022-32917 KEV The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7.… Patch first 7.8 high 5.6% 2022-09-20
CVE-2023-21823 KEV Windows Graphics Component Remote Code Execution Vulnerability Patch first 7.8 high 5.6% 2023-02-14
CVE-2022-0492 KEV A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circums… Patch first 7.8 high 5.5% 2022-03-03
CVE-2019-15271 KEV A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker… Patch first 8.8 high 5.5% 2019-11-26
CVE-2021-27085 KEV Internet Explorer Remote Code Execution Vulnerability Patch first 8.8 high 5.4% 2021-03-11
CVE-2020-17087 KEV Windows Kernel Local Elevation of Privilege Vulnerability Patch first 7.8 high 5.4% 2020-11-11
CVE-2021-28664 KEV The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/wr… Patch first 8.8 high 5.4% 2021-05-10
CVE-2021-30900 KEV An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.1 and iPadOS 15.… Patch first 7.8 high 5.2% 2021-08-24
CVE-2015-6175 KEV The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privi… Patch first 7.8 high 5.1% 2015-12-09
CVE-2026-25108 KEV FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted… Patch first 8.8 high 5.1% 2026-02-13
CVE-2025-13223 KEV Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… Patch first 8.8 high 5% 2025-11-17
CVE-2021-36741 KEV An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 al… Patch first 8.8 high 5% 2021-07-29
CVE-2009-1123 KEV The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate ch… Patch first 7.8 high 4.9% 2009-06-10
CVE-2020-1631 KEV A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirec… Patch first 8.8 high 4.8% 2020-05-04
CVE-2019-18988 KEV TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installation… Patch first 7.0 high 4.7% 2020-02-07
CVE-2025-60710 KEV Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges l… Patch first 7.8 high 4.6% 2025-11-11
CVE-2019-7287 KEV A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbit… Patch first 7.8 high 4.6% 2019-12-18
CVE-2020-1027 KEV An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privileg… Patch first 7.8 high 4.5% 2020-04-15
CVE-2026-20045 KEV A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME)… Patch first 8.2 high 4.5% 2026-01-21
CVE-2021-31979 KEV Windows Kernel Elevation of Privilege Vulnerability Patch first 7.8 high 4.5% 2021-07-14
CVE-2025-54313 KEV eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package exe… Patch first 7.5 high 4.5% 2025-07-19
CVE-2021-30661 KEV A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchO… Patch first 8.8 high 4.5% 2021-09-08
CVE-2023-46748 KEV An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network acces… Patch first 8.8 high 4.5% 2023-10-26
CVE-2023-41179 KEV A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Fr… Patch first 7.2 high 4.3% 2023-09-19
CVE-2018-8611 KEV An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Pr… Patch first 7.8 high 4.2% 2018-12-12
CVE-2023-32049 KEV Windows SmartScreen Security Feature Bypass Vulnerability Patch first 8.8 high 4.2% 2023-07-11
CVE-2019-0859 KEV An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation… Patch first 7.8 high 4.2% 2019-04-09
← previous page 24 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt