peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,553 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-31161 EXP Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via th… Patch early 10.0 critical 28.4% 2022-07-15
CVE-2018-12327 EXP Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges vi… Patch early 9.8 critical 28% 2018-06-20
CVE-2019-8982 EXP com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to discl… Patch early 9.6 critical 28% 2019-02-21
CVE-2018-9032 EXP An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version… Patch early 9.8 critical 27.7% 2018-03-27
CVE-2019-25024 EXP OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service paramete… Patch early 9.8 critical 27.6% 2021-02-19
CVE-2017-1002000 EXP Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/im… Patch early 9.8 critical 27.4% 2017-09-14
CVE-2017-16562 EXP The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and… Patch early 9.8 critical 27.4% 2017-11-10
CVE-2018-7750 EXP transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.… Patch early 9.8 critical 27.1% 2018-03-13
CVE-2016-4203 EXP Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… Patch early 9.8 critical 26.9% 2016-07-13
CVE-2020-35314 EXP A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to uploa… Patch early 9.8 critical 26.9% 2021-04-20
CVE-2007-5775 EXP Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029… Patch early 9.8 critical 26.9% 2007-11-01
CVE-2017-6359 EXP QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors. Patch early 9.8 critical 26.9% 2017-03-23
CVE-2020-11819 EXP In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution. Patch early 9.8 critical 26.8% 2020-04-16
CVE-2013-2570 EXP A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the bi… Patch early 9.8 critical 26.6% 2020-01-29
CVE-2013-6225 EXP LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability Patch early 9.8 critical 26.6% 2020-01-13
CVE-2018-8733 EXP Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to ma… Patch early 9.8 critical 26.6% 2018-04-18
CVE-2022-24627 EXP An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the… Patch early 9.8 critical 26.4% 2023-05-29
CVE-2019-19576 EXP class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar… Patch early 9.8 critical 26.4% 2019-12-04
CVE-2020-20277 EXP There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to impro… Patch early 9.8 critical 26.2% 2020-12-18
CVE-2018-17057 EXP An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper. Patch early 9.8 critical 26.2% 2018-09-14
CVE-2015-6024 EXP ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execu… Patch early 9.8 critical 26.1% 2017-02-09
CVE-2024-24724 EXP Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because in… Patch early 9.8 critical 26.1% 2024-04-03
CVE-2019-1913 EXP Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote atta… Patch early 9.8 critical 25.9% 2019-08-07
CVE-2018-15152 EXP Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal… Patch early 9.1 critical 25.9% 2018-08-15
CVE-2019-16072 EXP An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitr… Patch early 9.8 critical 25.9% 2020-03-20
CVE-2016-10036 EXP Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servl… Patch early 9.8 critical 25.6% 2018-05-01
CVE-2019-15106 EXP An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on th… Patch early 9.8 critical 25.5% 2019-08-16
CVE-2016-4138 EXP Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… Patch early 9.8 critical 25.4% 2016-06-16
CVE-2016-2851 EXP Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and app… Patch early 9.8 critical 25.4% 2016-04-07
CVE-2017-5586 EXP OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, re… Patch early 9.8 critical 25.3% 2017-02-22
← previous page 22 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt