peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,603 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

317,974 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-3928 KEV Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory:… Patch first 8.8 high 2.3% 2025-04-25
CVE-2025-32706 KEV Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 2.3% 2025-05-13
CVE-2019-0880 KEV A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerab… Patch first 7.8 high 2.3% 2019-07-15
CVE-2020-9818 KEV An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5.… Patch first 8.8 high 2.3% 2020-06-09
CVE-2022-41073 KEV Windows Print Spooler Elevation of Privilege Vulnerability Patch first 7.8 high 2.3% 2022-11-09
CVE-2021-1782 KEV A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 20… Patch first 7.0 high 2.2% 2021-04-02
CVE-2026-11645 KEV Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Patch first 8.8 high 2.2% 2026-06-09
CVE-2026-34621 KEV Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('… Patch first 8.6 high 2.2% 2026-04-11
CVE-2020-9819 KEV A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, wa… Patch first 4.3 medium 2.2% 2020-06-09
CVE-2025-24993 KEV Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Patch first 7.8 high 2.2% 2025-03-11
CVE-2017-12232 KEV A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through… Patch first 6.5 medium 2.2% 2017-09-29
CVE-2025-21043 KEV Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. Patch first 8.8 high 2.1% 2025-09-12
CVE-2025-32709 KEV Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 2.1% 2025-05-13
CVE-2017-6663 KEV A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker… Patch first 6.5 medium 2.1% 2017-08-07
CVE-2026-65660 KEV Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Patch first 8.8 high 2.1% 2026-08-11
CVE-2017-12238 KEV A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an u… Patch first 6.5 medium 2% 2017-09-29
CVE-2025-0111 KEV An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the manage… Patch first 6.5 medium 2% 2025-02-12
CVE-2020-2506 KEV The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers… Patch first 7.3 high 2% 2021-02-03
CVE-2025-24991 KEV Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Patch first 5.5 medium 2% 2025-03-11
CVE-2025-24984 KEV Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. Patch first 4.6 medium 2% 2025-03-11
CVE-2026-28318 KEV SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: defla… Patch first 7.5 high 1.9% 2026-06-04
CVE-2023-41974 KEV A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An ap… Patch first 7.8 high 1.9% 2024-01-10
CVE-2025-30400 KEV Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 1.9% 2025-05-13
CVE-2025-8875 KEV Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1. Patch first 7.8 high 1.9% 2025-08-14
CVE-2019-0797 KEV An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation… Patch first 7.8 high 1.9% 2019-04-09
CVE-2025-59689 KEV Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.3… Patch first 6.1 medium 1.9% 2025-09-19
CVE-2025-27920 KEV Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameter… Patch first 7.2 high 1.9% 2025-05-05
CVE-2024-7694 KEV ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on t… Patch first 7.2 high 1.8% 2024-08-12
CVE-2022-41091 KEV Windows Mark of the Web Security Feature Bypass Vulnerability Patch first 5.4 medium 1.8% 2022-11-09
CVE-2018-19322 KEV The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.2… Patch first 7.8 high 1.8% 2018-12-21
← previous page 33 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt