peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,514 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-8518 EXP Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution. Patch early 9.8 critical 71.7% 2020-02-17
CVE-2014-8684 EXP CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequen… Patch early 9.8 critical 71.7% 2017-09-19
CVE-2019-11231 EXP An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files with arbitrar… Patch early 9.8 critical 71.6% 2019-05-22
CVE-2018-20434 EXP LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during… Patch early 9.8 critical 71.5% 2019-04-24
CVE-2021-46419 EXP An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts. Patch early 9.1 critical 71.4% 2022-04-07
CVE-2016-1909 EXP Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4… Patch early 9.8 critical 71.3% 2016-01-15
CVE-2021-4039 EXP A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on t… Patch early 9.8 critical 71% 2022-03-01
CVE-2020-29597 EXP IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upl… Patch early 9.8 critical 71% 2020-12-07
CVE-2017-8895 EXP In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in… Patch early 9.8 critical 71% 2017-05-10
CVE-2016-5675 EXP handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR Ready… Patch early 9.8 critical 70.9% 2016-08-31
CVE-2021-35064 EXP KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous comm… Patch early 9.8 critical 70.8% 2021-07-12
CVE-2018-10094 EXP SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameter… Patch early 9.8 critical 70.7% 2018-05-22
CVE-2013-4211 EXP A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicio… Patch early 9.8 critical 70.7% 2020-02-14
CVE-2007-3798 EXP Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs i… Patch early 9.8 critical 70.4% 2007-07-16
CVE-2019-7257 EXP Linear eMerge E3-Series devices allow Unrestricted File Upload. Patch early 10.0 critical 70% 2019-07-02
CVE-2021-42071 EXP In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/log… Patch early 9.8 critical 69.9% 2021-10-07
CVE-2012-4284 EXP A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binar… Patch early 9.8 critical 69.5% 2020-01-10
CVE-2018-7573 EXP An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with the FTP 220 response code to cr… Patch early 9.8 critical 69.2% 2018-03-01
CVE-2021-34621 EXP A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it p… Patch early 9.8 critical 68.9% 2021-07-07
CVE-2013-3215 EXP vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. Patch early 9.8 critical 68.8% 2020-01-29
CVE-2018-10594 EXP Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS… Patch early 9.8 critical 68.6% 2018-06-26
CVE-2016-6195 EXP SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remot… Patch early 9.8 critical 68.5% 2016-08-30
CVE-2024-28000 EXP Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a th… Patch early 9.8 critical 68.3% 2024-08-21
CVE-2017-12477 EXP It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its… Patch early 9.8 critical 68.2% 2017-08-07
CVE-2012-5357 EXP Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attacker… Patch early 9.8 critical 67.8% 2017-10-30
CVE-2016-6662 EXP Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17;… Patch early 9.8 critical 67.7% 2016-09-20
CVE-2020-0610 EXP A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target sy… Patch early 9.8 critical 67.6% 2020-01-14
CVE-2026-23744 EXP MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vul… Patch early 9.8 critical 67.5% 2026-01-16
CVE-2012-0694 EXP SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code. Patch early 9.8 critical 67.3% 2019-10-29
CVE-2019-13101 EXP An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead… Patch early 9.8 critical 67.1% 2019-08-08
← previous page 14 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt