peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,672 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-16383 EXP MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attac… Patch early 9.4 critical 5.2% 2019-09-24
CVE-2021-37593 EXP PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the… Patch early 9.1 critical 5.2% 2021-07-30
CVE-2013-1744 EXP IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands. Patch early 9.8 critical 5.1% 2020-01-25
CVE-2017-7402 EXP Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager… Patch early 9.8 critical 5% 2017-04-03
CVE-2009-3421 EXP login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrativ… Patch early 9.8 critical 5% 2009-09-25
CVE-2026-26980 EXP Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the datab… Patch early 9.4 critical 5% 2026-02-20
CVE-2017-8837 EXP Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1… Patch early 9.8 critical 4.9% 2017-06-05
CVE-2012-5699 EXP BabyGekko before 1.2.4 allows PHP file inclusion. Patch early 9.8 critical 4.9% 2020-01-23
CVE-2017-15962 EXP iStock Management System 1.0 allows Arbitrary File Upload via user/profile. Patch early 9.8 critical 4.9% 2017-10-29
CVE-2018-6410 EXP An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter. Patch early 9.8 critical 4.9% 2018-05-26
CVE-2014-9612 EXP SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote… Patch early 9.8 critical 4.9% 2020-02-19
CVE-2018-5315 EXP The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. Patch early 9.8 critical 4.9% 2018-01-12
CVE-2012-5686 EXP ZPanel 10.0.1 has insufficient entropy for its password reset process. Patch early 9.8 critical 4.8% 2020-02-04
CVE-2005-0408 EXP CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass au… Patch early 9.8 critical 4.7% 2005-02-14
CVE-2021-43140 EXP SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login. Patch early 9.8 critical 4.7% 2021-11-03
CVE-2016-9488 EXP ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker… Patch early 9.8 critical 4.7% 2018-06-05
CVE-2013-2739 EXP MiniDLNA has heap-based buffer overflow Patch early 9.8 critical 4.7% 2019-11-01
CVE-2021-42136 EXP A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute J… Patch early 9.0 critical 4.7% 2022-04-13
CVE-2016-7400 EXP Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter… Patch early 9.8 critical 4.7% 2017-02-07
CVE-2012-5190 EXP Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability Patch early 9.8 critical 4.7% 2020-01-21
CVE-2018-12052 EXP SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php. Patch early 9.8 critical 4.6% 2018-06-08
CVE-2021-26830 EXP SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the… Patch early 9.1 critical 4.6% 2021-04-16
CVE-2002-1798 EXP MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access… Patch early 9.1 critical 4.6% 2002-12-31
CVE-2015-4523 EXP Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanis… Patch early 9.3 critical 4.5% 2017-09-11
CVE-2023-31703 EXP Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject a… Patch early 9.0 critical 4.5% 2023-05-17
CVE-2026-80428 EXP ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to ex… Patch early 9.8 critical 4.5% 2026-08-26
CVE-2006-4428 EXP PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary PHP code via a URL in the templ… Patch early 9.8 critical 4.4% 2006-08-29
CVE-2024-48841 EXP Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older. Patch early 10.0 critical 4.4% 2025-01-27
CVE-2023-23163 EXP Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter. Patch early 9.8 critical 4.4% 2023-02-10
CVE-2023-23162 EXP Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php. Patch early 9.8 critical 4.4% 2023-02-10
← previous page 39 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt