peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,482 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

148,896 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-0841 KEV EXP An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of… Patch first 7.8 high 41.4% 2019-04-09
CVE-2023-29336 KEV EXP Win32k Elevation of Privilege Vulnerability Patch first 7.8 high 40.9% 2023-05-09
CVE-2013-6282 KEV EXP The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, wh… Patch first 8.8 high 39.7% 2013-11-20
CVE-2013-3660 KEV EXP The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vi… Patch first 7.8 high 39.3% 2013-05-24
CVE-2019-11707 KEV EXP A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We… Patch first 8.8 high 37.7% 2019-07-23
CVE-2014-3153 KEV EXP The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which a… Patch first 7.8 high 37.2% 2014-06-07
CVE-2016-0099 KEV EXP The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold a… Patch first 7.8 high 36.8% 2016-03-09
CVE-2020-5735 KEV EXP Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to cras… Patch first 8.8 high 36.2% 2020-04-08
CVE-2017-6327 KEV EXP The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual ma… Patch first 8.8 high 35.9% 2017-08-11
CVE-2013-5065 KEV EXP NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as… Patch first 7.8 high 34.7% 2013-11-28
CVE-2017-6884 KEV EXP A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the d… Patch first 8.8 high 34.4% 2017-04-06
CVE-2008-4128 KEV EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Route… Patch first 8.1 high 33.9% 2008-09-18
CVE-2011-2005 KEV EXP afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to… Patch first 7.8 high 31.5% 2011-10-12
CVE-2025-26633 KEV EXP Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. Patch first 7.0 high 30.4% 2025-03-11
CVE-2019-1405 KEV EXP An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Win… Patch first 7.8 high 30% 2019-11-12
CVE-2010-0232 KEV EXP The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista G… Patch first 7.8 high 28.7% 2010-01-21
CVE-2024-38193 KEV EXP Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Patch first 7.8 high 28.5% 2024-08-13
CVE-2025-30397 KEV EXP Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a net… Patch first 7.5 high 26.8% 2025-05-13
CVE-2024-49138 KEV EXP Windows Common Log File System Driver Elevation of Privilege Vulnerability Patch first 7.8 high 26.2% 2024-12-12
CVE-2016-0040 KEV EXP The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted a… Patch first 7.8 high 24.5% 2016-02-10
CVE-2021-3560 KEV EXP It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the ro… Patch first 7.8 high 23.7% 2022-02-16
CVE-2016-4656 KEV EXP The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruptio… Patch first 7.8 high 23.6% 2016-08-25
CVE-2016-6367 KEV EXP Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges vi… Patch first 7.8 high 22.6% 2016-08-18
CVE-2020-24363 KEV EXP TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a fact… Patch first 8.8 high 20.7% 2020-08-31
CVE-2016-3309 KEV EXP The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R… Patch first 7.8 high 20.5% 2016-08-09
CVE-2019-1215 KEV EXP An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vu… Patch first 7.8 high 19.3% 2019-09-11
CVE-2019-1322 KEV EXP An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege… Patch first 7.8 high 19.2% 2019-10-10
CVE-2010-4345 KEV EXP Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration f… Patch first 7.8 high 18% 2010-12-14
CVE-2019-8605 KEV EXP A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1.… Patch first 7.8 high 17.6% 2019-12-18
CVE-2019-8506 KEV EXP A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.… Patch first 8.8 high 16.2% 2019-12-18
← previous page 7 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt