peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,483 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-23488 EXP The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of t… Patch early 9.8 critical 92.5% 2023-01-20
CVE-2017-12629 EXP Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-lis… Patch early 9.8 critical 91.9% 2017-10-14
CVE-2022-31814 EXP pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header… Patch early 9.8 critical 91.9% 2022-09-05
CVE-2018-10933 EXP A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without firs… Patch early 9.1 critical 91.8% 2018-10-17
CVE-2014-8739 EXP Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solu… Patch early 9.8 critical 91.7% 2020-02-08
CVE-2018-3810 EXP Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to inser… Patch early 9.8 critical 91.1% 2018-01-01
CVE-2016-6600 EXP Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and exec… Patch early 9.8 critical 90.6% 2017-01-23
CVE-2018-1207 EXP Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthe… Patch early 9.8 critical 90.1% 2018-03-23
CVE-2019-12725 EXP Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTT… Patch early 9.8 critical 89.8% 2019-07-19
CVE-2019-5420 EXP A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated deve… Patch early 9.8 critical 89.7% 2019-03-27
CVE-2018-14417 EXP A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not… Patch early 9.8 critical 89.6% 2018-08-04
CVE-2011-3923 EXP Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. Patch early 9.8 critical 89.5% 2019-11-01
CVE-2013-1359 EXP An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Ma… Patch early 9.8 critical 89.4% 2020-02-11
CVE-2018-15708 EXP Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request. Patch early 9.8 critical 89.4% 2018-11-14
CVE-2020-8794 EXP OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this… Patch early 9.8 critical 88.9% 2020-02-25
CVE-2019-2729 EXP Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected a… Patch early 9.8 critical 88.8% 2019-06-19
CVE-2024-25600 EXP Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bric… Patch early 10.0 critical 88.2% 2024-06-04
CVE-2021-20837 EXP Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and… Patch early 9.8 critical 88.1% 2021-10-26
CVE-2020-35729 EXP KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter. Patch early 9.8 critical 88.1% 2020-12-27
CVE-2017-17411 EXP This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to e… Patch early 9.8 critical 87.9% 2017-12-21
CVE-2018-7584 EXP In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an H… Patch early 9.8 critical 87.3% 2018-03-01
CVE-2021-32305 EXP WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter. Patch early 9.8 critical 87.3% 2021-05-18
CVE-2009-3555 EXP The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache H… Patch early 9.8 critical 87.3% 2009-11-09
CVE-2018-5999 EXP An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests conti… Patch early 9.8 critical 87.3% 2018-01-22
CVE-2017-12611 EXP In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can l… Patch early 9.8 critical 87.1% 2017-09-20
CVE-2016-6603 EXP ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header. Patch early 9.8 critical 87% 2017-01-23
CVE-2025-32429 EXP XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0… Patch early 9.8 critical 87% 2025-07-24
CVE-2018-1002105 EXP In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apis… Patch early 9.8 critical 87% 2018-12-05
CVE-2021-24762 EXP The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the… Patch early 9.8 critical 86.8% 2022-02-01
CVE-2018-0101 EXP A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthentic… Patch early 10.0 critical 86.8% 2018-01-29
← previous page 9 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt