peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,558 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-1930 EXP In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker t… Patch early 9.8 critical 20.5% 2019-11-14
CVE-2019-14348 EXP The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-york… Patch early 9.8 critical 20.5% 2019-08-05
CVE-2022-31125 EXP Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauth… Patch early 10.0 critical 20.3% 2022-07-06
CVE-2021-27828 EXP SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavi… Patch early 9.1 critical 20.3% 2021-06-01
CVE-2018-13416 EXP In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) att… Patch early 9.8 critical 20.2% 2018-08-03
CVE-2018-5973 EXP SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryI… Patch early 9.8 critical 20.1% 2018-01-25
CVE-2017-4901 EXP The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory acce… Patch early 9.9 critical 19.9% 2017-06-08
CVE-2019-9791 EXP The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMo… Patch early 9.8 critical 19.9% 2019-04-26
CVE-2007-1399 EXP Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to e… Patch early 9.8 critical 19.8% 2007-03-10
CVE-2021-43617 EXP Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttr… Patch early 9.8 critical 19.8% 2021-11-14
CVE-2018-5726 EXP MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request, as demonstrated by the usernam… Patch early 9.8 critical 19.8% 2018-01-16
CVE-2020-24215 EXP An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP re… Patch early 9.8 critical 19.8% 2020-10-06
CVE-2019-8049 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 19.7% 2019-08-20
CVE-2016-6175 EXP Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header… Patch early 9.8 critical 19.7% 2017-02-07
CVE-2019-8385 EXP An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability… Patch early 9.8 critical 19.6% 2019-06-05
CVE-2016-0951 EXP Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a… Patch early 9.8 critical 19.6% 2016-02-10
CVE-2016-0952 EXP Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a… Patch early 9.8 critical 19.6% 2016-02-10
CVE-2016-0953 EXP Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a… Patch early 9.8 critical 19.6% 2016-02-10
CVE-2021-3018 EXP ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print… Patch early 9.8 critical 19.5% 2021-01-05
CVE-2024-24496 EXP An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tr… Patch early 9.8 critical 19.5% 2024-02-08
CVE-2016-4071 EXP Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows r… Patch early 9.8 critical 19.5% 2016-05-20
CVE-2016-4372 EXP HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02,… Patch early 9.8 critical 19.4% 2016-07-15
CVE-2025-64459 EXP An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `Que… Patch early 9.1 critical 19.4% 2025-11-05
CVE-2017-14094 EXP A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution… Patch early 9.8 critical 19.4% 2018-01-19
CVE-2017-7997 EXP Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1) show_prn parameter… Patch early 9.8 critical 19.3% 2018-01-08
CVE-2019-19208 EXP Codiad Web IDE through 2.8.4 allows PHP Code injection. Patch early 9.8 critical 19.2% 2020-03-16
CVE-2016-6598 EXP BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service conta… Patch early 9.8 critical 19.2% 2018-01-30
CVE-2013-3684 EXP NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload Patch early 9.8 critical 19.2% 2020-02-11
CVE-2016-2208 EXP The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denia… Patch early 9.1 critical 19.2% 2016-05-19
CVE-2017-16949 EXP An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the at… Patch early 9.8 critical 19.2% 2017-12-19
← previous page 25 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt