peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-26

168,978 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-26829 KEV OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. Patch first 5.4 medium 48.1% 2021-06-11
CVE-2022-39197 KEV An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the C… Patch first 6.1 medium 46.4% 2022-09-22
CVE-2024-43573 KEV Windows MSHTML Platform Spoofing Vulnerability Patch first 6.5 medium 46.1% 2024-10-08
CVE-2013-3900 KEV Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and… Patch first 5.5 medium 44.6% 2013-12-11
CVE-2024-9379 KEV SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrar… Patch first 6.5 medium 43.8% 2024-10-08
CVE-2021-34448 KEV Scripting Engine Memory Corruption Vulnerability Patch first 6.8 medium 40.1% 2021-07-16
CVE-2021-39935 KEV An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, a… Patch first 6.8 medium 35.6% 2021-12-13
CVE-2026-20316 KEV A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log… Patch first 5.3 medium 35.1% 2026-07-29
CVE-2018-13383 KEV A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1… Patch first 4.3 medium 33.6% 2019-05-29
CVE-2015-0071 KEV Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explore… Patch first 6.5 medium 33.6% 2015-02-11
CVE-2016-3298 KEV Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 al… Patch first 6.5 medium 33.3% 2016-10-14
CVE-2020-8195 KEV Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SD… Patch first 6.5 medium 33% 2020-07-10
CVE-2020-35730 KEV An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mai… Patch first 6.1 medium 32.7% 2020-12-28
CVE-2026-20133 KEV A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system.… Patch first 6.5 medium 31.8% 2026-02-25
CVE-2022-24682 KEV An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starti… Patch first 6.1 medium 30.9% 2022-02-09
CVE-2018-6882 KEV Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 an… Patch first 6.1 medium 29.8% 2018-03-27
CVE-2025-68686 KEV An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7… Patch first 5.9 medium 29.6% 2026-02-10
CVE-2018-19953 KEV If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the f… Patch first 6.1 medium 28.8% 2020-10-28
CVE-2020-3153 KEV A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy… Patch first 6.5 medium 28.3% 2020-02-19
CVE-2026-20262 KEV A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a fil… Patch first 6.5 medium 28.2% 2026-06-15
CVE-2024-37085 KEV VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access… Patch first 6.8 medium 26.8% 2024-06-25
CVE-2020-8196 KEV Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWA… Patch first 4.3 medium 26.3% 2020-07-10
CVE-2016-3351 KEV Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Micros… Patch first 6.5 medium 26.3% 2016-09-14
CVE-2023-20269 KEV A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software… Patch first 5.0 medium 25.5% 2023-09-06
CVE-2026-20122 KEV A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local fi… Patch first 5.4 medium 25% 2026-02-25
CVE-2016-9563 KEV BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him… Patch first 6.5 medium 24.2% 2016-11-23
CVE-2024-27443 KEV An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of… Patch first 6.1 medium 23.6% 2024-08-12
CVE-2024-44309 KEV A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1… Patch first 6.3 medium 22.6% 2024-11-20
CVE-2016-0162 KEV Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explor… Patch first 4.3 medium 22% 2016-04-12
CVE-2023-36563 KEV Microsoft WordPad Information Disclosure Vulnerability Patch first 6.5 medium 20.7% 2023-10-10
← previous page 3 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt