peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,596 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-7079 EXP Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables a… Patch early 9.8 critical 12.9% 2007-03-02
CVE-2022-2840 EXP The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via vario… Patch early 9.8 critical 12.9% 2022-09-19
CVE-2018-9022 EXP An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands… Patch early 9.8 critical 12.8% 2018-06-18
CVE-2018-6911 EXP The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argumen… Patch early 9.8 critical 12.8% 2018-02-13
CVE-2018-8898 EXP A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer=… Patch early 9.8 critical 12.8% 2018-05-23
CVE-2020-6627 EXP The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_lau… Patch early 9.8 critical 12.8% 2022-12-06
CVE-2018-10285 EXP The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attack… Patch early 9.8 critical 12.8% 2018-04-22
CVE-2017-14097 EXP An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to decrypt… Patch early 9.8 critical 12.7% 2018-01-19
CVE-2014-9611 EXP Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/in… Patch early 9.8 critical 12.7% 2017-09-19
CVE-2017-1002002 EXP Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/ Patch early 9.8 critical 12.6% 2017-09-14
CVE-2017-14459 EXP An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a… Patch early 10.0 critical 12.6% 2018-04-11
CVE-2018-11509 EXP ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from t… Patch early 9.8 critical 12.6% 2018-08-16
CVE-2018-19861 EXP Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is… Patch early 9.8 critical 12.6% 2019-01-03
CVE-2018-19862 EXP Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is… Patch early 9.8 critical 12.6% 2019-01-03
CVE-2017-17976 EXP In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. Patch early 9.8 critical 12.5% 2018-01-26
CVE-2018-10824 EXP An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-… Patch early 9.8 critical 12.5% 2018-10-17
CVE-2016-7567 EXP Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a craf… Patch early 9.8 critical 12.5% 2017-01-23
CVE-2019-11448 EXP An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the s… Patch early 9.8 critical 12.4% 2019-04-22
CVE-2022-24082 EXP If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not… Patch early 9.8 critical 12.3% 2022-07-19
CVE-2017-1002003 EXP Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://… Patch early 9.8 critical 12.3% 2017-09-14
CVE-1999-0066 EXP AnyForm CGI remote execution. Patch early 9.8 critical 12.3% 1995-07-31
CVE-2018-7264 EXP The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign error… Patch early 9.8 critical 12.3% 2018-02-28
CVE-2016-6599 EXP BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service co… Patch early 9.8 critical 12.3% 2018-01-30
CVE-2017-11153 EXP Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain ad… Patch early 9.8 critical 12.2% 2017-08-08
CVE-2016-1741 EXP The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or… Patch early 9.8 critical 12.2% 2016-03-24
CVE-2017-5358 EXP Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argu… Patch early 9.8 critical 12.1% 2017-03-15
CVE-1999-0006 EXP Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command. Patch early 9.8 critical 12.1% 1998-07-14
CVE-2014-5289 EXP Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request. Patch early 9.8 critical 12% 2019-12-27
CVE-2014-8673 EXP Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPl… Patch early 9.8 critical 11.9% 2020-01-07
CVE-2021-33990 EXP Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue be… Patch early 9.8 critical 11.9% 2023-04-16
← previous page 31 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt