peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-26

205,428 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-22986 KEV EXP On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ… Patch first 9.8 critical 99.9% 2021-03-31
CVE-2014-0497 KEV EXP Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.33… Patch first 9.8 critical 99.9% 2014-02-05
CVE-2022-35914 KEV EXP /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection. Patch first 9.8 critical 99.9% 2022-09-19
CVE-2021-36260 KEV EXP A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vuln… Patch first 9.8 critical 99.9% 2021-09-22
CVE-2021-21972 KEV EXP The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 44… Patch first 9.8 critical 99.9% 2021-02-24
CVE-2025-24893 KEV EXP XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code e… Patch first 9.8 critical 99.9% 2025-02-20
CVE-2023-23752 KEV EXP An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. Patch first 5.3 medium 99.8% 2023-02-16
CVE-2022-46169 KEV EXP Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected v… Patch first 9.8 critical 99.8% 2022-12-05
CVE-2017-7269 KEV EXP Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003… Patch first 9.8 critical 99.8% 2017-03-27
CVE-2020-0796 KEV EXP A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka '… Patch first 10.0 critical 99.8% 2020-03-12
CVE-2025-55182 KEV EXP A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the f… Patch first 10.0 critical 99.8% 2025-12-03
CVE-2022-1040 KEV EXP An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 a… Patch first 9.8 critical 99.8% 2022-03-25
CVE-2025-32432 KEV EXP Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15… Patch first 10.0 critical 99.8% 2025-04-25
CVE-2020-13927 KEV EXP The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to use… Patch first 9.8 critical 99.8% 2020-11-10
CVE-2025-25257 KEV EXP An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.… Patch first 9.8 critical 99.8% 2025-07-17
CVE-2019-18935 KEV EXP Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploit… Patch first 9.8 critical 99.7% 2019-12-11
CVE-2021-22205 KEV EXP An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passe… Patch first 10.0 critical 99.7% 2021-04-23
CVE-2019-16759 KEV EXP vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. Patch first 9.8 critical 99.7% 2019-09-24
CVE-2010-2861 KEV EXP Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitra… Patch first 9.8 critical 99.7% 2010-08-11
CVE-2016-10033 KEV EXP The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and… Patch first 9.8 critical 99.7% 2016-12-30
CVE-2019-15107 KEV EXP An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability. Patch first 9.8 critical 99.7% 2019-08-16
CVE-2017-1000353 KEV EXP Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated rem… Patch first 9.8 critical 99.7% 2018-01-29
CVE-2018-20062 KEV EXP An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the f… Patch first 9.8 critical 99.5% 2018-12-11
CVE-2024-23692 KEV EXP Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, u… Patch first 9.8 critical 99.5% 2024-05-31
CVE-2018-0171 KEV EXP A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigge… Patch first 9.8 critical 99.5% 2018-03-28
CVE-2017-7494 KEV EXP Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upl… Patch first 9.8 critical 99.4% 2017-05-30
CVE-2020-1472 KEV EXP An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, us… Patch first 5.5 medium 99.4% 2020-08-17
CVE-2015-5119 KEV EXP Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x… Patch first 9.8 critical 99.3% 2015-07-08
CVE-2014-6287 KEV EXP The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to exec… Patch first 9.8 critical 99.3% 2014-10-07
CVE-2020-1938 KEV EXP When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as h… Patch first 9.8 critical 99.3% 2020-02-24
← previous page 3 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt