peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,806 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

398,806 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-31010 KEV A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and… Patch first 7.5 high 3.7% 2021-08-24
CVE-2018-19321 KEV The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.2… Patch first 7.8 high 3.7% 2018-12-21
CVE-2021-27102 KEV Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later. Patch first 7.8 high 3.7% 2021-02-16
CVE-2026-85880 KEV Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 3.6% 2026-09-08
CVE-2016-8562 KEV A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special condit… Patch first 7.5 high 3.6% 2016-11-18
CVE-2019-1385 KEV An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in acce… Patch first 7.8 high 3.6% 2019-11-12
CVE-2018-19320 KEV The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GUR… Patch first 7.8 high 3.6% 2018-12-21
CVE-2024-53197 KEV In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices… Patch first 7.8 high 3.6% 2024-12-27
CVE-2023-45727 KEV Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and ea… Patch first 7.5 high 3.5% 2023-10-18
CVE-2025-3935 KEV ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserv… Patch first 8.1 high 3.5% 2025-04-25
CVE-2021-30663 KEV An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 1… Patch first 8.8 high 3.5% 2021-09-08
CVE-2024-8068 KEV Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active… Patch first 8.0 high 3.5% 2024-11-12
CVE-2018-0175 KEV Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Softw… Patch first 8.0 high 3.5% 2018-03-28
CVE-2019-1315 KEV An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manage… Patch first 7.8 high 3.5% 2019-10-10
CVE-2021-35247 KEV Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanis… Patch first 4.3 medium 3.5% 2022-01-10
CVE-2025-8876 KEV Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. Patch first 8.8 high 3.4% 2025-08-14
CVE-2018-8406 KEV An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Gr… Patch first 7.8 high 3.4% 2018-08-15
CVE-2018-8405 KEV An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Gr… Patch first 7.8 high 3.4% 2018-08-15
CVE-2026-31431 KEV In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit… Patch first 7.8 high 3.4% 2026-04-22
CVE-2025-66644 KEV Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. Patch first 7.2 high 3.4% 2025-12-05
CVE-2024-53104 KEV In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format… Patch first 7.8 high 3.4% 2024-12-02
CVE-2018-0167 KEV Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco… Patch first 8.8 high 3.4% 2018-03-28
CVE-2020-3569 KEV Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, re… Patch first 8.6 high 3.3% 2020-09-23
CVE-2009-2055 KEV Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribu… Patch first 5.9 medium 3.3% 2009-08-19
CVE-2025-42599 KEV Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request create… Patch first 9.8 critical 3.3% 2025-04-18
CVE-2022-40139 KEV Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allo… Patch first 7.2 high 3.3% 2022-09-19
CVE-2022-32894 KEV An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1.… Patch first 7.8 high 3.3% 2022-08-24
CVE-2022-48503 KEV The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Saf… Patch first 8.8 high 3.2% 2023-08-14
CVE-2013-2596 KEV Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1… Patch first 7.8 high 3.2% 2013-04-13
CVE-2020-9934 KEV An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPad… Patch first 5.5 medium 3.2% 2020-10-16
← previous page 50 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt