peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,558 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

398,558 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-40449 KEV Win32k Elevation of Privilege Vulnerability Patch first 7.8 high 74.1% 2021-10-13
CVE-2019-1003029 KEV A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox… Patch first 9.9 critical 73.9% 2019-03-08
CVE-2025-40536 KEV SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated atta… Patch first 8.1 high 73.6% 2026-01-28
CVE-2025-6205 KEV A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access… Patch first 9.1 critical 73.3% 2025-08-04
CVE-2021-42278 KEV Active Directory Domain Services Elevation of Privilege Vulnerability Patch first 7.5 high 73.3% 2021-11-10
CVE-2023-47565 KEV An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerabilit… Patch first 8.0 high 73.3% 2023-12-08
CVE-2025-2746 KEV An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 u… Patch first 9.8 critical 73% 2025-03-24
CVE-2020-5741 KEV Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code. Patch first 7.2 high 72.9% 2020-05-08
CVE-2018-8414 KEV A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vu… Patch first 8.8 high 72.9% 2018-08-15
CVE-2022-20699 KEV Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… Patch first 10.0 critical 72.5% 2022-02-10
CVE-2021-25296 KEV Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/w… Patch first 8.8 high 72.2% 2021-02-15
CVE-2025-30066 KEV tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on… Patch first 8.6 high 72.1% 2025-03-15
CVE-2012-1856 KEV The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and… Patch first 8.8 high 72% 2012-08-15
CVE-2020-3259 KEV A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co… Patch first 7.5 high 71.8% 2020-05-06
CVE-2022-28810 KEV Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTE… Patch first 6.8 medium 71% 2022-04-18
CVE-2026-21962 KEV Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Pl… Patch first 10.0 critical 70.9% 2026-01-20
CVE-2026-21509 KEV Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. Patch first 7.8 high 70.8% 2026-01-26
CVE-2024-20353 KEV A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) So… Patch first 8.6 high 70.7% 2024-04-24
CVE-2025-20333 KEV A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FT… Patch first 9.9 critical 70.7% 2025-09-25
CVE-2020-36193 KEV Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue t… Patch first 7.5 high 70.6% 2021-01-18
CVE-2022-2294 KEV Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted… Patch first 8.8 high 70.5% 2022-07-28
CVE-2021-21220 KEV Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corrupt… Patch first 8.8 high 70.4% 2021-04-26
CVE-2020-4427 KEV IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with… Patch first 9.8 critical 70% 2020-05-07
CVE-2021-44026 KEV Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. Patch first 9.8 critical 69.9% 2021-11-19
CVE-2016-0034 KEV Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cau… Patch first 8.8 high 69.4% 2016-01-13
CVE-2020-0938 KEV A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted m… Patch first 7.8 high 69% 2020-04-15
CVE-2016-11021 KEV setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter. Patch first 7.2 high 68.9% 2020-03-09
CVE-2020-4430 KEV IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker co… Patch first 4.3 medium 68.5% 2020-05-07
CVE-2021-30657 KEV A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious… Patch first 5.5 medium 68.5% 2021-09-08
CVE-2016-3393 KEV Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Se… Patch first 7.8 high 68.5% 2016-10-14
← previous page 28 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt