peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,587 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

185,371 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-27104 KEV Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA… Patch first 9.8 critical 56.7% 2021-02-16
CVE-2021-25297 KEV Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/s… Patch first 8.8 high 56.7% 2021-02-15
CVE-2019-19006 KEV Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. Patch first 9.8 critical 55.9% 2019-11-21
CVE-2025-58034 KEV An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWe… Patch first 7.2 high 55.6% 2025-11-18
CVE-2022-37055 KEV D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main, Patch first 9.8 critical 55.5% 2022-08-28
CVE-2018-0125 KEV A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated… Patch first 9.8 critical 55.2% 2018-02-08
CVE-2022-29499 KEV The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Servi… Patch first 9.8 critical 55% 2022-04-26
CVE-2006-1547 KEV ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multi… Patch first 7.5 high 54.6% 2006-03-30
CVE-2014-4077 KEV Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IM… Patch first 7.8 high 54.6% 2014-11-11
CVE-2024-38812 KEV The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCent… Patch first 9.8 critical 54.6% 2024-09-17
CVE-2024-43461 KEV Windows MSHTML Platform Spoofing Vulnerability Patch first 8.8 high 54.5% 2024-09-10
CVE-2020-29557 KEV An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achie… Patch first 9.8 critical 54.3% 2021-01-29
CVE-2020-1054 KEV An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker… Patch first 7.0 high 54.2% 2020-05-21
CVE-2021-31196 KEV Microsoft Exchange Server Remote Code Execution Vulnerability Patch first 7.2 high 54.1% 2021-07-14
CVE-2020-25079 KEV An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated comman… Patch first 8.8 high 54% 2020-09-02
CVE-2022-21971 KEV Windows Runtime Remote Code Execution Vulnerability Patch first 7.8 high 53.9% 2022-02-09
CVE-2014-0130 KEV Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18,… Patch first 7.5 high 53.7% 2014-05-07
CVE-2021-22941 KEV Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the s… Patch first 9.8 critical 53.6% 2021-09-23
CVE-2023-41064 KEV A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS… Patch first 7.8 high 53.4% 2023-09-07
CVE-2025-14611 KEV Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degra… Patch first 9.8 critical 53.3% 2025-12-12
CVE-2023-45249 KEV Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-6… Patch first 9.8 critical 53.3% 2024-07-24
CVE-2015-1642 KEV Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memo… Patch first 7.8 high 53.1% 2015-08-15
CVE-2012-2539 KEV Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote… Patch first 7.8 high 53% 2012-12-12
CVE-2009-0557 KEV Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP… Patch first 7.8 high 53% 2009-06-10
CVE-2019-1367 KEV A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin… Patch first 7.5 high 52.4% 2019-09-23
CVE-2021-28550 KEV Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use… Patch first 8.8 high 52% 2021-09-02
CVE-2023-32434 KEV An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15… Patch first 7.8 high 51.5% 2023-06-23
CVE-2009-1537 KEV Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4,… Patch first 8.8 high 51.2% 2009-05-29
CVE-2025-53690 KEV Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issu… Patch first 9.0 critical 51.1% 2025-09-03
CVE-2015-2502 KEV Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf… Patch first 8.8 high 51% 2015-08-19
← previous page 29 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt