peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,558 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

185,361 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-42009 KEV A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim… Patch first 9.3 critical 82.9% 2024-08-05
CVE-2021-27561 KEV Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication. Patch first 9.8 critical 82.9% 2021-10-15
CVE-2023-27992 KEV The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior… Patch first 9.8 critical 82.8% 2023-06-19
CVE-2023-43208 KEV NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused b… Patch first 9.8 critical 82.7% 2023-10-26
CVE-2014-1776 KEV Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of servic… Patch first 9.8 critical 82.7% 2014-04-27
CVE-2021-23758 KEV All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET clas… Patch first 8.1 high 82.6% 2021-12-03
CVE-2025-34026 KEV The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at att… Patch first 7.5 high 81.9% 2025-05-21
CVE-2023-27532 KEV Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead… Patch first 7.5 high 81.3% 2023-03-10
CVE-2017-11826 KEV Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer,… Patch first 7.8 high 81.2% 2017-10-13
CVE-2017-0262 KEV Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle obj… Patch first 7.8 high 81% 2017-05-12
CVE-2024-43468 KEV Microsoft Configuration Manager Remote Code Execution Vulnerability Patch first 9.8 critical 80.9% 2024-10-08
CVE-2021-26411 KEV Internet Explorer Memory Corruption Vulnerability Patch first 8.8 high 80.8% 2021-03-11
CVE-2023-22952 KEV In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. Patch first 8.8 high 80.1% 2023-01-11
CVE-2013-1331 KEV Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Offi… Patch first 7.8 high 79.8% 2013-06-12
CVE-2020-10987 KEV The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceN… Patch first 9.8 critical 79.8% 2020-07-13
CVE-2024-8957 KEV PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_ad… Patch first 7.2 high 79.7% 2024-09-17
CVE-2023-49103 KEV An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.p… Patch first 10.0 critical 78.4% 2023-11-21
CVE-2021-1732 KEV Windows Win32k Elevation of Privilege Vulnerability Patch first 7.8 high 78.4% 2021-02-25
CVE-2021-21975 KEV Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vR… Patch first 7.5 high 78.3% 2021-03-31
CVE-2021-28799 KEV An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allo… Patch first 10.0 critical 78.3% 2021-05-13
CVE-2022-26318 KEV On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS be… Patch first 9.8 critical 78.2% 2022-03-04
CVE-2011-3402 KEV Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Se… Patch first 8.8 high 78.1% 2011-11-04
CVE-2017-0261 KEV Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle obj… Patch first 7.8 high 78.1% 2017-05-12
CVE-2023-27351 KEV This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is n… Patch first 7.5 high 78.1% 2023-04-20
CVE-2026-16232 KEV An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicatio… Patch first 9.8 critical 78% 2026-07-22
CVE-2025-6204 KEV An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an… Patch first 8.0 high 78% 2025-08-04
CVE-2026-8037 KEV OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary comm… Patch first 9.6 critical 77.4% 2026-06-04
CVE-2022-41080 KEV Microsoft Exchange Server Elevation of Privilege Vulnerability Patch first 8.8 high 77.3% 2022-11-09
CVE-2023-34192 KEV Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the… Patch first 9.0 critical 77.3% 2023-07-06
CVE-2021-42287 KEV Active Directory Domain Services Elevation of Privilege Vulnerability Patch first 7.5 high 77.2% 2021-11-10
← previous page 25 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt