peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,528 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-27964 EXP SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFil… Patch early 9.8 critical 47.5% 2021-03-05
CVE-2018-5767 EXP An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with… Patch early 9.8 critical 47.4% 2018-02-15
CVE-2015-6834 EXP Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary… Patch early 9.8 critical 46.8% 2016-05-16
CVE-2019-9879 EXP The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are all… Patch early 9.8 critical 46.6% 2019-06-10
CVE-2025-29306 EXP An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component. Patch early 9.8 critical 46.6% 2025-03-27
CVE-2023-30145 EXP Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. Patch early 9.8 critical 46.1% 2023-05-26
CVE-2015-9323 EXP The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection. Patch early 9.8 critical 46.1% 2019-08-16
CVE-2022-35411 EXP rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, althou… Patch early 9.8 critical 45.7% 2022-07-08
CVE-2019-6444 EXP An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data… Patch early 9.1 critical 45.7% 2019-01-16
CVE-2016-1606 EXP Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code v… Patch early 9.8 critical 45.6% 2016-07-03
CVE-2021-29003 EXP Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as… Patch early 9.8 critical 45.4% 2021-04-13
CVE-2018-15839 EXP D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header. Patch early 9.8 critical 45.3% 2018-08-28
CVE-2020-35313 EXP A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attack… Patch early 9.8 critical 45.2% 2021-04-20
CVE-2024-48760 EXP An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlc… Patch early 9.8 critical 45.1% 2025-01-14
CVE-2024-42640 EXP angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allow… Patch early 9.8 critical 45.1% 2024-10-11
CVE-2022-0332 EXP A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching u… Patch early 9.8 critical 44.9% 2022-01-25
CVE-2019-8341 EXP An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" paramet… Patch early 9.8 critical 44.8% 2019-02-15
CVE-2018-11510 EXP The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by… Patch early 9.8 critical 44.3% 2018-06-28
CVE-2020-36847 EXP The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which… Patch early 9.8 critical 44.2% 2025-07-12
CVE-2020-13693 EXP An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled. Patch early 9.8 critical 43.9% 2020-05-29
CVE-2014-8687 EXP Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use o… Patch early 9.8 critical 43.8% 2017-06-08
CVE-2019-9618 EXP The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter. Patch early 9.8 critical 43.8% 2019-05-13
CVE-2022-0482 EXP Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. Patch early 9.1 critical 43.7% 2022-03-09
CVE-2018-6317 EXP The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remo… Patch early 9.1 critical 43.7% 2018-02-02
CVE-2017-10366 EXP Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor). Supported versi… Patch early 9.8 critical 43.5% 2017-10-19
CVE-2010-1205 EXP Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to exe… Patch early 9.8 critical 43.4% 2010-06-30
CVE-2017-11346 EXP Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk… Patch early 9.8 critical 43.3% 2017-07-17
CVE-2025-68664 EXP LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability… Patch early 9.3 critical 42.9% 2025-12-23
CVE-2018-1235 EXP Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauth… Patch early 9.8 critical 42.9% 2018-05-29
CVE-2020-9374 EXP On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends spec… Patch early 9.8 critical 42.7% 2020-02-24
← previous page 18 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt