peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,514 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-6443 EXP An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_contro… Patch early 9.1 critical 66.9% 2019-01-16
CVE-2017-11394 EXP Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable install… Patch early 9.8 critical 66.8% 2017-08-03
CVE-2021-32172 EXP Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin. Patch early 9.8 critical 66.4% 2021-10-07
CVE-2021-37425 EXP Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobil… Patch early 9.1 critical 66.3% 2021-08-10
CVE-2012-2926 EXP Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, a… Patch early 9.1 critical 66.3% 2012-05-22
CVE-2017-6360 EXP QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors. Patch early 9.8 critical 66.1% 2017-03-23
CVE-2025-55315 EXP Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security fe… Patch early 9.9 critical 65.9% 2025-10-14
CVE-2019-10123 EXP SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker t… Patch early 9.8 critical 65.9% 2019-05-31
CVE-2017-14147 EXP An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its f… Patch early 9.8 critical 65.6% 2017-09-07
CVE-2016-10175 EXP The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user… Patch early 9.8 critical 65% 2017-01-30
CVE-2020-7115 EXP The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker coul… Patch early 9.8 critical 64.6% 2020-06-03
CVE-2018-6328 EXP It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unaut… Patch early 9.8 critical 64.4% 2018-03-14
CVE-2016-2296 EXP Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attack… Patch early 9.4 critical 64.3% 2016-05-14
CVE-2018-7297 EXP Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access a… Patch early 9.8 critical 64.3% 2018-02-22
CVE-2017-9417 EXP Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue. Patch early 9.8 critical 64% 2017-06-04
CVE-2017-11165 EXP dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /service… Patch early 9.8 critical 63.9% 2017-07-12
CVE-2018-16283 EXP The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. Patch early 9.8 critical 63.1% 2018-09-24
CVE-2012-0911 EXP TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1)… Patch early 9.8 critical 63% 2012-07-12
CVE-2026-0740 EXP The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Con… Patch early 9.8 critical 62.9% 2026-04-07
CVE-2024-8522 EXP The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress… Patch early 10.0 critical 62.9% 2024-09-12
CVE-2017-6622 EXP A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authenticati… Patch early 9.8 critical 62.2% 2017-05-18
CVE-2022-24223 EXP AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php. Patch early 9.8 critical 62% 2022-02-01
CVE-2016-1209 EXP The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in… Patch early 9.8 critical 61.6% 2016-05-14
CVE-2017-8835 EXP SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7… Patch early 9.8 critical 61.6% 2017-06-05
CVE-2018-16836 EXP Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbit… Patch early 9.8 critical 61.4% 2018-09-11
CVE-2018-6329 EXP It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote at… Patch early 9.8 critical 61.2% 2018-03-14
CVE-2017-5941 EXP An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to ach… Patch early 9.8 critical 61% 2017-02-09
CVE-2019-7304 EXP Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issu… Patch early 9.8 critical 60.8% 2019-04-23
CVE-2018-7756 EXP RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remot… Patch early 9.8 critical 60.7% 2018-03-15
CVE-2017-15222 EXP Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code. Patch early 9.8 critical 60.3% 2017-10-24
← previous page 15 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt