peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-26

168,978 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-37976 KEV Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information fr… Patch first 6.5 medium 19.9% 2021-10-08
CVE-2023-36761 KEV Microsoft Word Information Disclosure Vulnerability Patch first 6.5 medium 19.6% 2023-09-12
CVE-2021-41379 KEV Windows Installer Elevation of Privilege Vulnerability Patch first 5.5 medium 19.5% 2021-11-10
CVE-2024-20359 KEV A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Secur… Patch first 6.0 medium 19.4% 2024-04-24
CVE-2014-2120 KEV Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to injec… Patch first 6.1 medium 18.8% 2014-03-19
CVE-2020-11899 KEV The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. Patch first 5.4 medium 18.6% 2020-06-17
CVE-2019-5591 KEV A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impers… Patch first 6.5 medium 18.4% 2020-08-14
CVE-2017-0022 KEV Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1… Patch first 6.5 medium 18.1% 2017-03-17
CVE-2023-42916 KEV An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 1… Patch first 6.5 medium 17.8% 2023-11-30
CVE-2024-11182 KEV An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img… Patch first 6.1 medium 17.7% 2024-11-15
CVE-2022-27926 KEV A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthe… Patch first 6.1 medium 17.6% 2022-04-21
CVE-2021-30533 KEV Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via… Patch first 6.5 medium 16.6% 2021-06-07
CVE-2020-27950 KEV A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020… Patch first 5.5 medium 16.5% 2020-12-08
CVE-2024-20481 KEV A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)… Patch first 5.8 medium 15.8% 2024-10-23
CVE-2023-50224 KEV TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to di… Patch first 6.5 medium 15.6% 2024-05-03
CVE-2023-28204 KEV An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and… Patch first 6.5 medium 14.3% 2023-06-23
CVE-2024-12686 KEV A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative… Patch first 6.6 medium 13.7% 2024-12-18
CVE-2024-38213 KEV Windows Mark of the Web Security Feature Bypass Vulnerability Patch first 6.5 medium 13.6% 2024-08-13
CVE-2015-4902 KEV Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deploymen… Patch first 5.3 medium 13.6% 2015-10-22
CVE-2023-41991 KEV A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypa… Patch first 5.5 medium 13.4% 2023-09-21
CVE-2022-22948 KEV The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative acc… Patch first 6.5 medium 13.3% 2022-03-29
CVE-2022-20821 KEV A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is… Patch first 6.5 medium 11.5% 2022-05-26
CVE-2025-48927 KEV The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the… Patch first 5.3 medium 11.1% 2025-05-28
CVE-2022-41328 KEV A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.… Patch first 6.7 medium 10.7% 2023-03-07
CVE-2022-41223 KEV The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attac… Patch first 6.8 medium 10.7% 2022-11-22
CVE-2022-40765 KEV A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal… Patch first 6.8 medium 10.6% 2022-11-22
CVE-2022-2586 KEV It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was… Patch first 5.3 medium 10.2% 2024-01-08
CVE-2024-38217 KEV Windows Mark of the Web Security Feature Bypass Vulnerability Patch first 5.4 medium 10% 2024-09-10
CVE-2019-0703 KEV An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosur… Patch first 6.5 medium 9.6% 2019-04-09
CVE-2019-0676 KEV An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this… Patch first 6.5 medium 8.1% 2019-03-05
← previous page 4 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt