peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,587 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

185,377 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-38094 KEV Microsoft SharePoint Remote Code Execution Vulnerability Patch first 7.2 high 50.9% 2024-07-09
CVE-2023-49897 KEV An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vul… Patch first 8.8 high 50.4% 2023-12-06
CVE-2020-12812 KEV An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succes… Patch first 9.8 critical 49.3% 2020-07-24
CVE-2021-3493 KEV The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files i… Patch first 8.8 high 49.2% 2021-04-17
CVE-2011-1889 KEV The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitra… Patch first 9.8 critical 49% 2011-06-16
CVE-2023-5217 KEV Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exp… Patch first 8.8 high 49% 2023-09-28
CVE-2015-1671 KEV The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live… Patch first 7.8 high 49% 2015-05-13
CVE-2023-28252 KEV Windows Common Log File System Driver Elevation of Privilege Vulnerability Patch first 7.8 high 49% 2023-04-11
CVE-2026-85046 KEV Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML… Patch first 8.8 high 48.9% 2026-09-03
CVE-2025-68645 KEV A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling o… Patch first 8.8 high 48.9% 2025-12-22
CVE-2020-9715 KEV Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-a… Patch first 7.8 high 48.6% 2020-08-19
CVE-2022-23227 KEV NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because o… Patch first 9.8 critical 48.5% 2022-01-14
CVE-2020-16009 KEV Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a craf… Patch first 8.8 high 48.3% 2020-11-03
CVE-2016-1646 KEV The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider eleme… Patch first 8.8 high 48.1% 2016-03-29
CVE-2006-2492 KEV Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-ass… Patch first 8.8 high 48.1% 2006-05-20
CVE-2021-40407 KEV An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], base… Patch first 7.2 high 47.6% 2022-01-28
CVE-2023-48365 KEV Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of… Patch first 9.6 critical 47.5% 2023-11-15
CVE-2026-39808 KEV A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.… Patch first 9.8 critical 47.4% 2026-04-14
CVE-2021-22893 KEV Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Puls… Patch first 10.0 critical 47.2% 2021-04-23
CVE-2014-4123 KEV Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privil… Patch first 8.8 high 47.1% 2014-10-15
CVE-2019-1579 KEV Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProt… Patch first 8.1 high 46.2% 2019-07-19
CVE-2026-12569 KEV A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited th… Patch first 9.8 critical 46% 2026-06-18
CVE-2026-34910 KEV A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command I… Patch first 10.0 critical 45.8% 2026-05-22
CVE-2017-6862 KEV NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and re… Patch first 9.8 critical 45.7% 2017-05-26
CVE-2017-16651 KEV Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, in… Patch first 7.8 high 45.7% 2017-11-09
CVE-2017-6737 KEV A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely ex… Patch first 8.8 high 45.2% 2017-07-17
CVE-2024-29988 KEV SmartScreen Prompt Security Feature Bypass Vulnerability Patch first 8.8 high 44.9% 2024-04-09
CVE-2015-2425 KEV Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si… Patch first 8.8 high 44.7% 2015-07-14
CVE-2020-15999 KEV Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafte… Patch first 9.6 critical 44.3% 2020-11-03
CVE-2014-100005 KEV Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to h… Patch first 8.0 high 43.5% 2015-01-13
← previous page 30 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt