peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,831 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

398,831 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-45659 KEV Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Patch first 8.8 high 2.7% 2026-05-22
CVE-2024-36971 KEV In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce p… Patch first 7.8 high 2.7% 2024-06-10
CVE-2020-0878 KEV <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in… Patch first 4.2 medium 2.7% 2020-09-11
CVE-2023-29492 KEV Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not prov… Patch first 9.8 critical 2.7% 2023-04-11
CVE-2024-38226 KEV Microsoft Publisher Security Feature Bypass Vulnerability Patch first 7.3 high 2.7% 2024-09-10
CVE-2020-24557 KEV A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particula… Patch first 7.8 high 2.7% 2020-09-01
CVE-2025-59230 KEV Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 2.7% 2025-10-14
CVE-2019-6223 KEV A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1… Patch first 7.5 high 2.6% 2019-03-05
CVE-2021-31201 KEV Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability Patch first 5.2 medium 2.6% 2021-06-08
CVE-2023-35674 KEV In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local es… Patch first 7.8 high 2.6% 2023-09-11
CVE-2026-59310 KEV VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this is… Patch first 9.8 critical 2.6% 2026-07-30
CVE-2023-21492 KEV Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. Patch first 4.4 medium 2.6% 2023-05-04
CVE-2026-6973 KEV An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative… Patch first 7.2 high 2.5% 2026-05-07
CVE-2025-62221 KEV Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 2.5% 2025-12-09
CVE-2026-7273 KEV A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based… Patch first 8.8 high 2.5% 2026-06-16
CVE-2022-41049 KEV Windows Mark of the Web Security Feature Bypass Vulnerability Patch first 5.4 medium 2.5% 2022-11-09
CVE-2025-32975 KEV Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5),… Patch first 10.0 critical 2.5% 2025-06-24
CVE-2023-20109 KEV A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authentica… Patch first 6.6 medium 2.5% 2023-09-27
CVE-2026-21519 KEV Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 2.5% 2026-02-10
CVE-2025-30154 KEV reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 U… Patch first 8.6 high 2.4% 2025-03-19
CVE-2022-21919 KEV Windows User Profile Service Elevation of Privilege Vulnerability Patch first 7.0 high 2.4% 2022-01-11
CVE-2022-0028 KEV A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) at… Patch first 8.6 high 2.4% 2022-08-10
CVE-2018-4344 KEV A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watc… Patch first 7.8 high 2.4% 2019-04-03
CVE-2020-0638 KEV An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker wou… Patch first 7.8 high 2.4% 2020-01-14
CVE-2022-26486 KEV An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the… Patch first 9.6 critical 2.3% 2022-12-22
CVE-2025-21391 KEV Windows Storage Elevation of Privilege Vulnerability Patch first 7.1 high 2.3% 2025-02-11
CVE-2025-3928 KEV Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory:… Patch first 8.8 high 2.3% 2025-04-25
CVE-2025-53521 KEV When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Softwa… Patch first 9.8 critical 2.3% 2025-10-15
CVE-2025-32706 KEV Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Patch first 7.8 high 2.3% 2025-05-13
CVE-2019-0880 KEV A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerab… Patch first 7.8 high 2.3% 2019-07-15
← previous page 52 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt