peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,528 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

25,086 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-8617 EXP Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successful… Patch early 7.5 high 93.4% 2020-05-19
CVE-2018-6892 EXP An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listeni… Patch early 9.8 critical 93.4% 2018-02-11
CVE-2019-7276 EXP Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console. Patch early 9.8 critical 93.4% 2019-07-01
CVE-2016-3081 EXP Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execu… Patch early 8.1 high 93.4% 2016-04-26
CVE-2017-14492 EXP Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted… Patch early 9.8 critical 93.3% 2017-10-03
CVE-2005-1983 EXP Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to exe… Patch early 10.0 high 93% 2005-08-10
CVE-2016-4010 EXP Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialize… Patch early 9.8 critical 92.9% 2017-01-23
CVE-2019-15976 EXP Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker… Patch early 9.8 critical 92.8% 2020-01-06
CVE-2022-21907 EXP HTTP Protocol Stack Remote Code Execution Vulnerability Patch early 9.8 critical 92.8% 2022-01-11
CVE-2020-2096 EXP Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability. Patch early 6.1 medium 92.8% 2020-01-15
CVE-2022-21371 EXP Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 1… Patch early 7.5 high 92.6% 2022-01-19
CVE-2019-8943 EXP WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an a… Patch early 6.5 medium 92.6% 2019-02-20
CVE-2018-16509 EXP An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions… Patch early 7.8 high 92.5% 2018-09-05
CVE-2023-23488 EXP The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of t… Patch early 9.8 critical 92.5% 2023-01-20
CVE-2006-2369 EXP RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a… Patch early 7.5 high 92.4% 2006-05-15
CVE-2009-3103 EXP Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, an… Patch early 10.0 high 92.3% 2009-09-08
CVE-2016-0492 EXP Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows rem… Patch early 6.4 medium 92.1% 2016-01-21
CVE-2015-0359 EXP Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457… Patch early 10.0 high 92.1% 2015-04-14
CVE-2018-14912 EXP cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgi… Patch early 7.5 high 92% 2018-08-03
CVE-2010-1870 EXP The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly oth… Patch early 5.0 medium 92% 2010-08-17
CVE-2019-0227 EXP A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits… Patch early 7.5 high 91.9% 2019-05-01
CVE-2017-12629 EXP Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-lis… Patch early 9.8 critical 91.9% 2017-10-14
CVE-2022-31814 EXP pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header… Patch early 9.8 critical 91.9% 2022-09-05
CVE-2018-10933 EXP A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without firs… Patch early 9.1 critical 91.8% 2018-10-17
CVE-2001-0414 EXP Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute… Patch early 10.0 high 91.7% 2001-06-18
CVE-2014-8739 EXP Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solu… Patch early 9.8 critical 91.7% 2020-02-08
CVE-2019-9193 EXP In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute ar… Patch early 7.2 high 91.7% 2019-04-01
CVE-2008-0226 EXP Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code v… Patch early 7.5 high 91.6% 2008-01-10
CVE-2017-16806 EXP The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory traversal. Patch early 7.5 high 91.5% 2017-11-13
CVE-2014-0569 EXP Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Ado… Patch early 9.3 high 91.3% 2014-10-15
← previous page 20 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt