peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,648 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

318,006 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-48543 KEV In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to lo… Patch first 8.8 high 0.5% 2025-09-04
CVE-2026-34926 KEV A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the se… Patch first 6.7 medium 0.5% 2026-05-21
CVE-2021-1906 KEV Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdra… Patch first 6.2 medium 0.5% 2021-05-07
CVE-2026-42897 KEV Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to p… Patch first 8.1 high 0.5% 2026-05-14
CVE-2022-48618 KEV The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker… Patch first 7.0 high 0.5% 2024-01-09
CVE-2024-29745 KEV there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution pri… Patch first 5.5 medium 0.5% 2024-04-05
CVE-2025-21480 KEV Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. Patch first 8.6 high 0.5% 2025-06-03
CVE-2022-22071 KEV Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapd… Patch first 8.4 high 0.5% 2022-06-14
CVE-2026-41091 KEV Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 0.4% 2026-05-20
CVE-2025-43520 KEV A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1,… Patch first 5.5 medium 0.4% 2025-12-12
CVE-2021-25394 KEV A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege… Patch first 6.4 medium 0.4% 2021-06-11
CVE-2026-33825 KEV Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 0.4% 2026-04-14
CVE-2026-81963 KEV Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 0.4% 2026-09-08
CVE-2022-22265 KEV An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution… Patch first 5.0 medium 0.4% 2022-01-10
CVE-2021-25395 KEV A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is com… Patch first 6.4 medium 0.4% 2021-06-11
CVE-2025-43510 KEV A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26… Patch first 7.8 high 0.4% 2025-12-12
CVE-2026-56155 KEV Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally… Patch first 7.8 high 0.3% 2026-07-14
CVE-2026-68820 KEV Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Patch first 7.0 high 0.3% 2026-08-11
CVE-2026-3502 KEV TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update deli… Patch first 7.8 high 0.3% 2026-03-30
CVE-2023-21237 KEV In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insuffici… Patch first 5.5 medium 0.3% 2023-06-28
CVE-2025-48633 KEV In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in t… Patch first 5.5 medium 0.3% 2025-12-08
CVE-2025-48572 KEV In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalati… Patch first 7.8 high 0.3% 2025-12-08
CVE-2026-87886 KEV Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) befor… Patch first 7.8 high 0.2% 2026-09-17
CVE-2014-3704 EXP The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which all… Patch early 7.5 high 100% 2014-10-16
CVE-2015-7297 EXP SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different… Patch early 7.5 high 100% 2015-10-29
CVE-2019-0232 EXP When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93… Patch early 8.1 high 99.9% 2019-04-15
CVE-2020-13379 EXP The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/clien… Patch early 8.2 high 99.9% 2020-06-03
CVE-2008-2938 EXP Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 a… Patch early 4.3 medium 99.7% 2008-08-13
CVE-2020-14181 EXP Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabilit… Patch early 5.3 medium 99.6% 2020-09-17
CVE-2020-16040 EXP Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a craft… Patch early 6.5 medium 99.6% 2021-01-08
← previous page 37 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt