peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,579 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

205,481 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-43200 KEV This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPa… Patch first 4.2 medium 1.2% 2025-06-16
CVE-2022-22674 KEV An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixe… Patch first 5.5 medium 1.1% 2022-05-26
CVE-2023-36851 KEV A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attac… Patch first 5.3 medium 1.1% 2023-09-27
CVE-2021-25369 KEV An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. Patch first 6.2 medium 1.1% 2021-03-26
CVE-2023-4211 KEV A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. Patch first 5.5 medium 1.1% 2023-10-01
CVE-2026-93952 KEV VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and… Patch first 10.0 critical 1.1% 2026-09-22
CVE-2026-45321 KEV On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The… Patch first 9.6 critical 1.1% 2026-05-12
CVE-2026-67279 KEV RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenti… Patch first 6.5 medium 1% 2026-09-05
CVE-2026-8452 KEV Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the applianc… Patch first 9.8 critical 1% 2026-06-30
CVE-2026-48172 KEV LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best… Patch first 9.8 critical 1% 2026-05-21
CVE-2026-56164 KEV Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. Patch first 5.3 medium 1% 2026-07-14
CVE-2026-16812 KEV VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and… Patch first 10.0 critical 1% 2026-07-27
CVE-2026-85102 KEV Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to e… Patch first 9.8 critical 1% 2026-09-09
CVE-2026-32201 KEV Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Patch first 6.5 medium 1% 2026-04-14
CVE-2026-8398 KEV A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distribu… Patch first 9.8 critical 1% 2026-05-15
CVE-2026-84869 KEV A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host… Patch first 9.9 critical 0.9% 2026-09-08
CVE-2021-25370 KEV An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel pani… Patch first 6.1 medium 0.9% 2021-03-26
CVE-2021-0920 KEV In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with… Patch first 6.4 medium 0.8% 2021-12-15
CVE-2026-46817 KEV Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2… Patch first 9.8 critical 0.8% 2026-05-28
CVE-2024-50302 KEV In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by… Patch first 5.5 medium 0.8% 2024-11-19
CVE-2021-25372 KEV An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. Patch first 6.1 medium 0.8% 2021-03-26
CVE-2021-25371 KEV A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. Patch first 6.1 medium 0.8% 2021-03-26
CVE-2025-1976 KEV Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary… Patch first 6.7 medium 0.7% 2025-04-24
CVE-2026-66384 KEV An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. Patch first 5.3 medium 0.7% 2026-08-12
CVE-2026-7473 KEV On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Ge… Patch first 5.8 medium 0.6% 2026-06-05
CVE-2026-5430 KEV The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to… Patch first 10.0 critical 0.6% 2026-08-06
CVE-2025-48928 KEV The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a p… Patch first 4.0 medium 0.6% 2025-05-28
CVE-2026-34926 KEV A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the se… Patch first 6.7 medium 0.5% 2026-05-21
CVE-2021-1906 KEV Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdra… Patch first 6.2 medium 0.5% 2021-05-07
CVE-2024-29745 KEV there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution pri… Patch first 5.5 medium 0.5% 2024-04-05
← previous page 27 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt