peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,587 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-6315 EXP Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx. Patch early 9.8 critical 16.6% 2017-09-19
CVE-2017-8051 EXP Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of t… Patch early 9.8 critical 16.5% 2017-04-21
CVE-2018-13784 EXP PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php. Patch early 9.1 critical 16.5% 2018-07-09
CVE-2018-18761 EXP SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. Patch early 9.8 critical 16.5% 2018-11-16
CVE-2025-20125 EXP A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information,… Patch early 9.1 critical 16.4% 2025-02-05
CVE-2017-11151 EXP A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files wit… Patch early 9.8 critical 16.3% 2017-08-08
CVE-2018-14485 EXP BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. Patch early 9.8 critical 16.3% 2019-05-07
CVE-2012-6649 EXP WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload. Patch early 9.8 critical 16.3% 2020-01-23
CVE-2020-11749 EXP Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can tri… Patch early 9.0 critical 16.2% 2020-07-13
CVE-2013-2571 EXP Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request… Patch early 9.8 critical 16.2% 2020-01-28
CVE-2021-36711 EXP WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled. Patch early 9.8 critical 16.1% 2022-07-16
CVE-2019-8375 EXP The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script… Patch early 9.8 critical 16.1% 2019-02-24
CVE-2013-7137 EXP The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting th… Patch early 9.8 critical 16.1% 2014-01-26
CVE-2005-2103 EXP Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly e… Patch early 9.8 critical 16.1% 2005-08-16
CVE-2015-8396 EXP Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDC… Patch early 10.0 critical 16% 2016-01-12
CVE-2019-8045 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 16% 2019-08-20
CVE-2017-12785 EXP The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, is prone to a… Patch early 9.8 critical 16% 2017-08-22
CVE-2020-23935 EXP Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". Patch early 9.8 critical 15.9% 2020-08-20
CVE-2020-10230 EXP CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parame… Patch early 9.8 critical 15.8% 2020-03-16
CVE-2016-7866 EXP Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code… Patch early 9.8 critical 15.8% 2016-12-15
CVE-2017-3549 EXP Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affec… Patch early 9.1 critical 15.8% 2017-04-24
CVE-2025-4094 EXP The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightfo… Patch early 9.8 critical 15.8% 2025-05-21
CVE-2021-43136 EXP An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platfor… Patch early 9.8 critical 15.7% 2021-11-10
CVE-2017-12965 EXP Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter. Patch early 9.8 critical 15.7% 2017-08-23
CVE-2021-38759 EXP Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges. Patch early 9.8 critical 15.7% 2021-12-07
CVE-2015-8352 EXP Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act… Patch early 9.8 critical 15.6% 2017-08-24
CVE-2017-15580 EXP osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's co… Patch early 9.8 critical 15.6% 2017-10-23
CVE-2014-6437 EXP Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors in… Patch early 9.8 critical 15.5% 2018-01-12
CVE-2022-2651 EXP Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5. Patch early 9.8 critical 15.4% 2022-08-04
CVE-2022-35583 EXP wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial… Patch early 9.8 critical 15.4% 2022-08-22
← previous page 28 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt