peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,603 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

185,378 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-4523 KEV The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bou… Patch first 7.5 high 31.2% 2016-06-09
CVE-2020-0968 KEV A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin… Patch first 7.5 high 30.7% 2020-04-15
CVE-2021-27852 KEV Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary c… Patch first 9.8 critical 30.3% 2021-05-27
CVE-2021-20028 KEV Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specificall… Patch first 9.8 critical 30.1% 2021-08-04
CVE-2019-3568 KEV A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target pho… Patch first 9.8 critical 30.1% 2019-05-14
CVE-2019-13608 KEV Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks. Patch first 7.5 high 30% 2019-08-29
CVE-2025-32756 KEV A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCa… Patch first 9.8 critical 29.8% 2025-05-13
CVE-2017-0222 KEV A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vu… Patch first 8.8 high 29.6% 2017-05-12
CVE-2018-8653 KEV A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engin… Patch first 7.5 high 29.6% 2018-12-20
CVE-2026-20963 KEV Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Patch first 9.8 critical 29.6% 2026-01-13
CVE-2018-20753 KEV Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads… Patch first 9.8 critical 29.3% 2019-02-05
CVE-2023-2533 KEV A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an… Patch first 8.4 high 29.2% 2023-06-20
CVE-2017-0149 KEV Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft… Patch first 8.8 high 29.2% 2017-03-17
CVE-2014-3931 KEV fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption. Patch first 9.8 critical 29% 2017-03-31
CVE-2021-30807 KEV A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watc… Patch first 7.8 high 28.8% 2021-10-19
CVE-2023-33010 KEV A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmwar… Patch first 9.8 critical 28.8% 2023-05-24
CVE-2018-19949 KEV If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the fol… Patch first 9.8 critical 28.4% 2020-10-28
CVE-2024-3393 KEV A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malic… Patch first 7.5 high 28.4% 2024-12-27
CVE-2024-11120 KEV Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject an… Patch first 9.8 critical 28.4% 2024-11-15
CVE-2022-37969 KEV Windows Common Log File System Driver Elevation of Privilege Vulnerability Patch first 7.8 high 28.3% 2022-09-13
CVE-2026-76461 KEV A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execu… Patch first 9.8 critical 28.3% 2026-09-14
CVE-2019-19356 KEV Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been fou… Patch first 7.5 high 28.2% 2020-02-07
CVE-2023-33009 KEV A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware… Patch first 9.8 critical 28.1% 2023-05-24
CVE-2024-1086 KEV A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft… Patch first 7.8 high 28.1% 2024-01-31
CVE-2023-36802 KEV Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability Patch first 7.8 high 27.9% 2023-09-12
CVE-2024-21351 KEV Windows SmartScreen Security Feature Bypass Vulnerability Patch first 7.6 high 27.8% 2024-02-13
CVE-2025-27363 KEV An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subg… Patch first 8.1 high 27.8% 2025-03-11
CVE-2018-8581 KEV An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." Thi… Patch first 7.4 high 27.4% 2018-11-14
CVE-2023-28205 KEV A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 a… Patch first 8.8 high 27.1% 2023-04-10
CVE-2018-4063 KEV An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially craft… Patch first 8.8 high 27.1% 2019-05-06
← previous page 33 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt