peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,503 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-1495 EXP install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter. Patch early 9.8 critical 79.8% 2020-01-27
CVE-2016-6563 EXP Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnera… Patch early 9.8 critical 79.7% 2018-07-13
CVE-2016-2555 EXP SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the sea… Patch early 9.8 critical 79.6% 2017-04-13
CVE-2018-10662 EXP An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. Patch early 9.8 critical 79.5% 2018-06-26
CVE-2018-7890 EXP A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredenti… Patch early 9.8 critical 78.8% 2018-03-08
CVE-2021-24931 EXP The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_exp… Patch early 9.8 critical 78.8% 2021-12-06
CVE-2024-42327 EXP A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerabilit… Patch early 9.9 critical 78.7% 2024-11-27
CVE-2019-15954 EXP An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on th… Patch early 9.9 critical 78.7% 2019-09-05
CVE-2020-35665 EXP An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include… Patch early 9.8 critical 78.5% 2020-12-23
CVE-2025-2294 EXP The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_t… Patch early 9.8 critical 78.4% 2025-03-28
CVE-2019-9851 EXP LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained w… Patch early 9.8 critical 78.3% 2019-08-15
CVE-2017-12478 EXP It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not… Patch early 9.8 critical 78.3% 2017-08-07
CVE-2003-0466 EXP Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demons… Patch early 9.8 critical 78.1% 2003-08-27
CVE-2015-0936 EXP Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH acce… Patch early 9.8 critical 78.1% 2017-06-01
CVE-2020-0609 EXP A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target sy… Patch early 9.8 critical 77.7% 2020-01-14
CVE-2018-9059 EXP Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code via a malicious login request… Patch early 9.8 critical 77.6% 2018-04-20
CVE-2020-13166 EXP The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers… Patch early 9.8 critical 77.6% 2020-05-19
CVE-2016-10176 EXP The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This… Patch early 9.8 critical 77.6% 2017-01-30
CVE-2017-14143 EXP The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers to… Patch early 9.8 critical 77.4% 2017-09-19
CVE-2020-8012 EXP CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller)… Patch early 9.8 critical 77.4% 2020-02-18
CVE-2014-8741 EXP Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write t… Patch early 9.8 critical 77.2% 2020-01-27
CVE-2016-0854 EXP Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech… Patch early 9.8 critical 77% 2016-01-15
CVE-2017-9101 EXP import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP cod… Patch early 9.8 critical 76.7% 2017-05-21
CVE-2018-14728 EXP upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter. Patch early 9.8 critical 76.5% 2018-08-03
CVE-2019-1937 EXP A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Di… Patch early 9.8 critical 75.9% 2019-08-21
CVE-2017-1092 EXP IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM X… Patch early 9.8 critical 75.8% 2017-05-22
CVE-2022-2884 EXP A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated… Patch early 9.9 critical 75.7% 2022-10-17
CVE-2004-0847 EXP The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted director… Patch early 9.8 critical 75.7% 2004-11-03
CVE-2022-1162 EXP A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7… Patch early 9.1 critical 75.6% 2022-04-04
CVE-2018-9160 EXP SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses. Patch early 9.8 critical 75.6% 2018-03-31
← previous page 12 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt