peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,482 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

205,454 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-3043 KEV EXP Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to… Patch first 9.8 critical 73.9% 2015-04-14
CVE-2024-37383 KEV EXP Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. Patch first 6.1 medium 73.3% 2024-06-07
CVE-2017-6316 KEV EXP Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On… Patch first 9.8 critical 73% 2017-07-20
CVE-2019-9978 KEV EXP The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as explo… Patch first 6.1 medium 72.9% 2019-03-24
CVE-2018-7841 KEV EXP A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper se… Patch first 9.8 critical 72.7% 2019-05-22
CVE-2010-4344 KEV EXP Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMT… Patch first 9.8 critical 71.7% 2010-12-14
CVE-2016-2386 KEV EXP SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspeci… Patch first 9.8 critical 71.5% 2016-02-16
CVE-2017-6077 KEV EXP ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metac… Patch first 9.8 critical 68.7% 2017-02-22
CVE-2013-3896 KEV EXP Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to… Patch first 5.5 medium 68% 2013-10-09
CVE-2013-2729 KEV EXP Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code… Patch first 9.8 critical 66.6% 2013-05-16
CVE-2026-0770 KEV EXP Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote a… Patch first 9.8 critical 63.8% 2026-01-23
CVE-2019-8394 KEV EXP Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. Patch first 6.5 medium 63.3% 2019-02-17
CVE-2017-0059 KEV EXP Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Inter… Patch first 4.3 medium 62% 2017-03-17
CVE-2019-5786 KEV EXP Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access vi… Patch first 6.5 medium 61.1% 2019-06-27
CVE-2025-32463 KEV EXP Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot op… Patch first 9.3 critical 61% 2025-06-30
CVE-2018-7445 KEV EXP A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the… Patch first 9.8 critical 60.8% 2018-03-19
CVE-2025-24054 KEV EXP External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. Patch first 6.5 medium 58.9% 2025-03-11
CVE-2019-5825 KEV EXP Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafte… Patch first 6.5 medium 55.9% 2019-11-25
CVE-2019-11708 KEV EXP Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent p… Patch first 10.0 critical 55.9% 2019-07-23
CVE-2016-2388 KEV EXP The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP requ… Patch first 5.3 medium 52.2% 2016-02-16
CVE-2013-5223 KEV EXP Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web scr… Patch first 5.4 medium 50.8% 2013-11-19
CVE-2026-39987 KEV EXP marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks aut… Patch first 9.8 critical 37.9% 2026-04-09
CVE-2018-13374 KEV EXP A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LD… Patch first 4.3 medium 37.8% 2019-01-22
CVE-2016-4655 KEV EXP The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app. Patch first 5.5 medium 33.4% 2016-08-25
CVE-2026-56290 KEV EXP Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable… Patch first 9.8 critical 30.9% 2026-06-29
CVE-2018-2380 KEV EXP SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characte… Patch first 6.6 medium 28.9% 2018-03-01
CVE-2026-9198 KEV EXP IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with… Patch first 9.8 critical 28.7% 2026-07-17
CVE-2026-33017 KEV EXP Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}… Patch first 9.8 critical 24.8% 2026-03-20
CVE-2014-0196 KEV EXP The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST"… Patch first 5.5 medium 22.5% 2014-05-07
CVE-2025-24085 KEV EXP A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15… Patch first 10.0 critical 17.5% 2025-01-27
← previous page 7 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt