peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,903 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

398,903 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-46817 KEV Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2… Patch first 9.8 critical 0.8% 2026-05-28
CVE-2024-50302 KEV In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by… Patch first 5.5 medium 0.8% 2024-11-19
CVE-2026-54420 KEV LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web sh… Patch first 8.5 high 0.8% 2026-06-14
CVE-2021-25372 KEV An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. Patch first 6.1 medium 0.8% 2021-03-26
CVE-2021-25371 KEV A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. Patch first 6.1 medium 0.8% 2021-03-26
CVE-2024-4610 KEV Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improp… Patch first 7.8 high 0.8% 2024-06-07
CVE-2024-43093 KEV In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive direct… Patch first 7.3 high 0.7% 2024-11-13
CVE-2026-53362 KEV In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), w… Patch first 7.8 high 0.7% 2026-07-04
CVE-2026-3909 KEV Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTM… Patch first 8.8 high 0.7% 2026-03-13
CVE-2026-5281 KEV Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrar… Patch first 8.8 high 0.7% 2026-04-01
CVE-2019-8526 KEV A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain… Patch first 7.8 high 0.7% 2019-12-18
CVE-2023-33063 KEV Memory corruption in DSP Services during a remote call from HLOS to DSP. Patch first 7.8 high 0.7% 2023-12-05
CVE-2025-1976 KEV Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary… Patch first 6.7 medium 0.7% 2025-04-24
CVE-2021-39793 KEV In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local… Patch first 7.8 high 0.7% 2022-03-16
CVE-2024-43047 KEV Memory corruption while maintaining memory maps of HLOS memory. Patch first 7.8 high 0.7% 2024-10-07
CVE-2024-29748 KEV there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pri… Patch first 7.8 high 0.7% 2024-04-05
CVE-2026-66384 KEV An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. Patch first 5.3 medium 0.7% 2026-08-12
CVE-2026-7473 KEV On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Ge… Patch first 5.8 medium 0.6% 2026-06-05
CVE-2026-53266 KEV In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target k… Patch first 8.8 high 0.6% 2026-06-25
CVE-2021-25487 KEV Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in ar… Patch first 7.3 high 0.6% 2021-10-06
CVE-2026-58704 KEV In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of… Patch first 8.8 high 0.6% 2026-09-15
CVE-2026-5430 KEV The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to… Patch first 10.0 critical 0.6% 2026-08-06
CVE-2025-48928 KEV The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a p… Patch first 4.0 medium 0.6% 2025-05-28
CVE-2025-48543 KEV In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to lo… Patch first 8.8 high 0.5% 2025-09-04
CVE-2026-34926 KEV A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the se… Patch first 6.7 medium 0.5% 2026-05-21
CVE-2021-25489 KEV Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug l… Patch first 3.3 low 0.5% 2021-10-06
CVE-2021-1906 KEV Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdra… Patch first 6.2 medium 0.5% 2021-05-07
CVE-2026-42897 KEV Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to p… Patch first 8.1 high 0.5% 2026-05-14
CVE-2022-48618 KEV The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker… Patch first 7.0 high 0.5% 2024-01-09
CVE-2024-29745 KEV there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution pri… Patch first 5.5 medium 0.5% 2024-04-05
← previous page 57 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt