peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,587 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-22832 EXP An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request. Patch early 9.8 critical 14.1% 2022-02-06
CVE-2018-7702 EXP SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary re… Patch early 9.1 critical 14% 2018-03-15
CVE-2013-4659 EXP Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on route… Patch early 9.8 critical 13.9% 2017-03-14
CVE-2015-7874 EXP Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname. Patch early 9.8 critical 13.9% 2020-01-15
CVE-2018-12463 EXP An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to… Patch early 9.8 critical 13.8% 2018-07-12
CVE-2017-18001 EXP Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys dat… Patch early 9.8 critical 13.8% 2017-12-31
CVE-2019-8660 EXP A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3.… Patch early 9.8 critical 13.8% 2019-12-18
CVE-2021-33216 EXP An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer… Patch early 9.8 critical 13.8% 2021-07-07
CVE-2009-4491 EXP thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or… Patch early 9.8 critical 13.7% 2010-01-13
CVE-2019-6971 EXP An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management web… Patch early 9.8 critical 13.7% 2019-06-19
CVE-2002-1484 EXP DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other sy… Patch early 9.8 critical 13.7% 2003-04-22
CVE-2015-0565 EXP NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible. Patch early 10.0 critical 13.6% 2020-02-25
CVE-2015-7241 EXP XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01. Patch early 9.8 critical 13.5% 2017-09-06
CVE-2017-16934 EXP The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content… Patch early 9.8 critical 13.5% 2017-11-24
CVE-2019-8647 EXP A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. A remote attacker may b… Patch early 9.8 critical 13.5% 2019-12-18
CVE-2016-9269 EXP Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_B… Patch early 9.9 critical 13.4% 2017-02-21
CVE-2015-8556 EXP Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1. Patch early 10.0 critical 13.4% 2017-03-24
CVE-2016-9796 EXP Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024. An at… Patch early 9.8 critical 13.4% 2016-12-03
CVE-2019-8017 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 13.3% 2019-08-20
CVE-2020-35775 EXP CITSmart before 9.1.2.23 allows LDAP Injection. Patch early 9.8 critical 13.3% 2021-02-15
CVE-2019-8613 EXP A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may… Patch early 9.8 critical 13.3% 2019-12-18
CVE-2019-9792 EXP The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value c… Patch early 9.8 critical 13.2% 2019-04-26
CVE-2013-4982 EXP AVTECH AVN801 DVR has a security bypass via the administration login captcha Patch early 9.8 critical 13.1% 2019-12-27
CVE-2013-2748 EXP Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system. Patch early 9.8 critical 13.1% 2020-01-28
CVE-2019-4013 EXP IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code… Patch early 9.0 critical 13% 2019-04-10
CVE-2009-4488 EXP Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or… Patch early 9.8 critical 13% 2010-01-13
CVE-2017-7462 EXP Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory. Patch early 9.8 critical 13% 2017-04-11
CVE-2006-6863 EXP PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PH… Patch early 9.8 critical 13% 2006-12-31
CVE-2019-15039 EXP An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1. Patch early 9.8 critical 12.9% 2019-10-01
CVE-2024-27746 EXP SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email ad… Patch early 9.8 critical 12.9% 2024-03-01
← previous page 30 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt