peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,558 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-15367 EXP Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depe… Patch early 9.8 critical 23.1% 2018-03-07
CVE-2023-48292 EXP The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior to version 4.5.1, a cross site… Patch early 9.6 critical 22.9% 2023-11-20
CVE-2021-44596 EXP Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can commu… Patch early 9.8 critical 22.9% 2022-04-29
CVE-2019-8196 EXP Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… Patch early 9.8 critical 22.9% 2019-10-17
CVE-2019-8195 EXP Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… Patch early 9.8 critical 22.9% 2019-10-17
CVE-2015-8617 EXP Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute… Patch early 9.8 critical 22.8% 2016-01-19
CVE-2018-6871 EXP LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.M… Patch early 9.8 critical 22.8% 2018-02-09
CVE-2016-9565 EXP MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing… Patch early 9.8 critical 22.7% 2016-12-15
CVE-2019-17124 EXP Kramer VIAware 2.5.0719.1034 has Incorrect Access Control. Patch early 9.8 critical 22.5% 2019-10-09
CVE-2018-19126 EXP PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload. Patch early 9.8 critical 22.5% 2018-11-09
CVE-2018-12596 EXP Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via… Patch early 9.8 critical 22.4% 2018-10-10
CVE-2016-3987 EXP The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefa… Patch early 9.8 critical 22.3% 2016-04-12
CVE-2017-3077 EXP Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful exploitatio… Patch early 9.8 critical 22.3% 2017-06-20
CVE-2003-0899 EXP Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '… Patch early 9.8 critical 22.2% 2003-11-03
CVE-2019-8016 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 22% 2019-08-20
CVE-2017-3623 EXP Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are affected see n… Patch early 10.0 critical 22% 2017-04-24
CVE-2018-8057 EXP A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/ad… Patch early 9.8 critical 21.8% 2018-03-11
CVE-2017-6542 EXP The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent proto… Patch early 9.8 critical 21.8% 2017-03-27
CVE-2018-20525 EXP Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php. Patch early 9.1 critical 21.6% 2019-03-21
CVE-2017-3195 EXP Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnera… Patch early 9.8 critical 21.4% 2017-12-16
CVE-2017-6548 EXP Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC… Patch early 9.8 critical 21.3% 2017-03-09
CVE-2016-9899 EXP Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Fi… Patch early 9.8 critical 21.1% 2018-06-11
CVE-2018-5159 EXP An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-… Patch early 9.8 critical 21% 2018-06-11
CVE-2021-26599 EXP ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. Patch early 9.8 critical 21% 2022-03-28
CVE-2016-4201 EXP Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… Patch early 9.8 critical 20.8% 2016-07-13
CVE-2018-13417 EXP In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.… Patch early 9.8 critical 20.7% 2018-08-13
CVE-2022-40032 EXP SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execu… Patch early 9.8 critical 20.7% 2023-02-17
CVE-2018-6481 EXP A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending… Patch early 9.8 critical 20.7% 2018-02-27
CVE-2015-6018 EXP The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary comm… Patch early 9.8 critical 20.6% 2015-12-31
CVE-2015-4664 EXP An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands. Patch early 9.8 critical 20.6% 2018-06-18
← previous page 24 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt