peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,519 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-24499 EXP The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks,… Patch early 9.8 critical 60.1% 2021-08-09
CVE-2012-2576 EXP SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWi… Patch early 9.8 critical 59.4% 2017-12-20
CVE-2019-5485 EXP NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository na… Patch early 10.0 critical 58.8% 2019-09-13
CVE-2019-14931 EXP An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote… Patch early 9.8 critical 58.1% 2019-10-28
CVE-2008-0081 EXP Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to… Patch early 9.8 critical 57.9% 2008-01-16
CVE-2018-7314 EXP SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. Patch early 9.8 critical 57.8% 2018-02-22
CVE-2018-6605 EXP SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHov… Patch early 9.8 critical 57.7% 2018-02-05
CVE-2016-8582 EXP A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve da… Patch early 9.8 critical 57.4% 2016-10-28
CVE-2017-6526 EXP An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected admi… Patch early 9.8 critical 57.4% 2017-03-09
CVE-2020-15922 EXP There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) pr… Patch early 9.8 critical 57.3% 2020-07-24
CVE-2019-5029 EXP An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands s… Patch early 9.8 critical 57.2% 2019-11-13
CVE-2019-5434 EXP An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in t… Patch early 9.8 critical 57% 2019-05-06
CVE-2021-45428 EXP TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HT… Patch early 9.8 critical 56.9% 2022-01-03
CVE-2017-6361 EXP QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors. Patch early 9.8 critical 56.8% 2017-03-23
CVE-2018-12634 EXP CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html… Patch early 9.8 critical 56.4% 2018-06-22
CVE-2018-17173 EXP LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. Patch early 9.8 critical 56.2% 2018-09-21
CVE-2016-3078 EXP Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffe… Patch early 9.8 critical 56.1% 2016-08-07
CVE-2011-4908 EXP TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php. Patch early 9.8 critical 55.8% 2020-02-12
CVE-2019-8387 EXP MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. Patch early 9.8 critical 55.7% 2019-05-08
CVE-2014-7236 EXP Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenablep… Patch early 9.1 critical 55.6% 2020-02-17
CVE-2021-43857 EXP Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched… Patch early 9.8 critical 55.3% 2021-12-27
CVE-2016-6602 EXP ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartex… Patch early 9.8 critical 55.1% 2017-01-23
CVE-2022-36267 EXP In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can… Patch early 9.8 critical 54.5% 2022-08-08
CVE-2022-24562 EXP In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the enti… Patch early 9.8 critical 54.5% 2022-06-16
CVE-2024-11972 EXP The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install an… Patch early 9.8 critical 54.5% 2024-12-31
CVE-2025-49132 EXP Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespac… Patch early 10.0 critical 54.5% 2025-06-20
CVE-2021-36356 EXP KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary e… Patch early 9.8 critical 54.4% 2021-08-31
CVE-2018-5347 EXP Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because… Patch early 9.8 critical 54.2% 2018-01-12
CVE-2019-6441 EXP An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The passw… Patch early 9.8 critical 53.6% 2019-03-21
CVE-2017-17932 EXP A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute ar… Patch early 9.8 critical 53.6% 2017-12-28
← previous page 16 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt