peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

168,985 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-20805 KEV Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. Patch first 5.5 medium 7.2% 2026-01-13
CVE-2021-1879 KEV This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. P… Patch first 6.1 medium 7.1% 2021-04-02
CVE-2026-48710 KEV Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to recon… Patch first 6.5 medium 7.1% 2026-05-26
CVE-2013-1675 KEV Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initial… Patch first 6.5 medium 6.7% 2013-05-16
CVE-2021-22600 KEV A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or d… Patch first 6.6 medium 6.5% 2022-01-26
CVE-2012-0767 KEV Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris… Patch first 6.1 medium 6.4% 2012-02-16
CVE-2026-60137 KEV WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which co… Patch first 5.9 medium 5.9% 2026-07-17
CVE-2019-6693 KEV Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup fi… Patch first 6.5 medium 5.8% 2019-11-21
CVE-2017-12319 KEV A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthen… Patch first 5.9 medium 5.2% 2018-03-27
CVE-2021-38000 KEV Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily brows… Patch first 6.1 medium 4.9% 2021-11-23
CVE-2018-0179 KEV Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trig… Patch first 5.9 medium 4.9% 2018-03-28
CVE-2018-0180 KEV Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trig… Patch first 5.9 medium 4.9% 2018-03-28
CVE-2025-47827 KEV In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a cr… Patch first 4.6 medium 4.9% 2025-06-05
CVE-2004-1464 KEV Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP co… Patch first 5.9 medium 4.8% 2004-12-31
CVE-2026-21525 KEV Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. Patch first 6.2 medium 4.8% 2026-02-10
CVE-2013-3993 KEV IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted da… Patch first 6.5 medium 4.8% 2014-07-07
CVE-2012-0518 KEV Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to… Patch first 4.7 medium 4.7% 2012-10-16
CVE-2022-2856 KEV Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily bro… Patch first 6.5 medium 4.5% 2022-09-26
CVE-2025-24200 KEV An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.… Patch first 6.1 medium 4.5% 2025-02-10
CVE-2024-20399 KEV A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary c… Patch first 6.0 medium 4.3% 2024-07-01
CVE-2025-55177 KEV Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, an… Patch first 5.4 medium 4.3% 2025-08-29
CVE-2021-20035 KEV Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as… Patch first 6.5 medium 4.2% 2021-09-27
CVE-2018-0161 KEV A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches… Patch first 6.3 medium 4.1% 2018-03-28
CVE-2015-1769 KEV Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and… Patch first 6.6 medium 4.1% 2015-08-15
CVE-2025-27915 KEV An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic W… Patch first 5.4 medium 4% 2025-03-12
CVE-2021-35247 KEV Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanis… Patch first 4.3 medium 3.5% 2022-01-10
CVE-2009-2055 KEV Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribu… Patch first 5.9 medium 3.3% 2009-08-19
CVE-2020-9934 KEV An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPad… Patch first 5.5 medium 3.2% 2020-10-16
CVE-2023-6548 KEV Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP… Patch first 5.5 medium 3.2% 2024-01-17
CVE-2021-27562 KEV In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when ca… Patch first 5.5 medium 3.1% 2021-05-25
← previous page 5 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt