peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,528 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-6553 EXP Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server v… Patch early 9.8 critical 42.3% 2017-04-29
CVE-2013-2573 EXP A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G,… Patch early 9.8 critical 42.2% 2020-01-29
CVE-2009-1936 EXP _functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attac… Patch early 9.8 critical 42.2% 2009-06-05
CVE-2014-6436 EXP Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in oppo… Patch early 9.8 critical 42.1% 2018-01-12
CVE-2018-3811 EXP SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL q… Patch early 9.8 critical 42% 2018-01-01
CVE-2016-10074 EXP The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail… Patch early 9.8 critical 41.8% 2016-12-30
CVE-2013-1595 EXP A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field se… Patch early 9.8 critical 41.6% 2020-01-24
CVE-2024-0132 EXP NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a sp… Patch early 9.0 critical 40.8% 2024-09-26
CVE-2019-8050 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 40.6% 2019-08-20
CVE-2015-4455 EXP Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows… Patch early 9.8 critical 40.6% 2017-05-23
CVE-2021-45092 EXP Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter. Patch early 9.8 critical 40.6% 2021-12-16
CVE-2013-1599 EXP A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01,… Patch early 9.8 critical 40.4% 2020-01-28
CVE-2020-24217 EXP An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentic… Patch early 9.8 critical 40.3% 2020-10-06
CVE-2019-7442 EXP An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attacker… Patch early 9.8 critical 40% 2019-05-08
CVE-2019-7269 EXP Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution. Patch early 9.8 critical 40% 2019-07-02
CVE-2025-7441 EXP The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs th… Patch early 9.8 critical 39.8% 2025-08-16
CVE-2018-10088 EXP Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725. Patch early 9.8 critical 39.7% 2018-06-08
CVE-2017-17968 EXP A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbi… Patch early 9.8 critical 39.6% 2017-12-29
CVE-2023-2068 EXP The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using t… Patch early 9.8 critical 39.6% 2023-06-27
CVE-2019-17240 EXP bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-… Patch early 9.8 critical 39.6% 2019-10-06
CVE-2017-12943 EXP D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path trav… Patch early 9.8 critical 39.2% 2017-08-18
CVE-2020-25494 EXP Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels paramete… Patch early 9.8 critical 39.2% 2020-12-18
CVE-2018-5262 EXP A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context… Patch early 9.8 critical 39.1% 2018-01-12
CVE-2018-17440 EXP An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has… Patch early 9.8 critical 38.5% 2018-10-08
CVE-2016-10034 EXP The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before… Patch early 9.8 critical 38.4% 2016-12-30
CVE-2021-3817 EXP wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command Patch early 9.8 critical 38.4% 2021-12-09
CVE-2018-14009 EXP Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689. Patch early 9.8 critical 38% 2018-07-12
CVE-2019-10945 EXP An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to ac… Patch early 9.8 critical 38% 2019-04-10
CVE-2014-5007 EXP Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Provid… Patch early 9.8 critical 37.3% 2020-01-17
CVE-2022-25359 EXP On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files. Patch early 9.1 critical 37.3% 2022-02-26
← previous page 19 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt