peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,612 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

317,979 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-32701 KEV Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 1.4% 2025-05-13
CVE-2025-21335 KEV Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability Patch first 7.8 high 1.4% 2025-01-14
CVE-2023-41990 KEV The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big… Patch first 7.8 high 1.4% 2023-09-12
CVE-2020-0069 KEV In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing… Patch first 7.8 high 1.4% 2020-03-10
CVE-2024-53150 KEV In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current… Patch first 7.1 high 1.4% 2024-12-24
CVE-2025-24983 KEV Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. Patch first 7.0 high 1.3% 2025-03-11
CVE-2026-20700 KEV A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3,… Patch first 7.8 high 1.3% 2026-02-11
CVE-2025-35939 KEV Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an… Patch first 5.3 medium 1.3% 2025-05-07
CVE-2024-49035 KEV An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. Patch first 8.7 high 1.3% 2024-11-26
CVE-2023-4346 KEV KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users bei… Patch first 7.5 high 1.3% 2023-08-29
CVE-2025-38352 KEV In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_… Patch first 7.8 high 1.3% 2025-07-22
CVE-2026-45498 KEV Microsoft Defender Denial of Service Vulnerability Patch first 4.0 medium 1.3% 2026-05-20
CVE-2026-21385 KEV Memory corruption while using alignments for memory allocation. Patch first 7.8 high 1.2% 2026-03-02
CVE-2025-43200 KEV This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPa… Patch first 4.2 medium 1.2% 2025-06-16
CVE-2022-22674 KEV An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixe… Patch first 5.5 medium 1.1% 2022-05-26
CVE-2023-36851 KEV A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attac… Patch first 5.3 medium 1.1% 2023-09-27
CVE-2021-25369 KEV An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. Patch first 6.2 medium 1.1% 2021-03-26
CVE-2023-4211 KEV A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. Patch first 5.5 medium 1.1% 2023-10-01
CVE-2022-22706 KEV Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, B… Patch first 7.8 high 1.1% 2022-03-03
CVE-2022-42827 KEV An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16.… Patch first 7.8 high 1% 2022-11-01
CVE-2026-67279 KEV RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenti… Patch first 6.5 medium 1% 2026-09-05
CVE-2026-3910 KEV Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Patch first 8.8 high 1% 2026-03-13
CVE-2021-23874 KEV Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execut… Patch first 8.2 high 1% 2021-02-10
CVE-2025-22225 KEV VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write… Patch first 8.2 high 1% 2025-03-04
CVE-2025-27038 KEV Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. Patch first 7.5 high 1% 2025-06-03
CVE-2026-56164 KEV Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. Patch first 5.3 medium 1% 2026-07-14
CVE-2026-20349 KEV A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Th… Patch first 8.6 high 1% 2026-08-11
CVE-2021-1048 KEV In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privil… Patch first 7.8 high 1% 2021-12-15
CVE-2025-39964 KEV In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes… Patch first 7.8 high 1% 2025-10-13
CVE-2026-32201 KEV Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Patch first 6.5 medium 1% 2026-04-14
← previous page 35 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt