peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,482 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

615 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-57819 KEV EXP FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-sup… Patch first 9.8 critical 85.5% 2025-08-28
CVE-2020-5722 KEV EXP The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker ca… Patch first 9.8 critical 84.4% 2020-03-23
CVE-2017-11317 KEV EXP Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remo… Patch first 9.8 critical 84.2% 2017-08-23
CVE-2020-3161 KEV EXP A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a… Patch first 9.8 critical 83.9% 2020-04-15
CVE-2016-10174 KEV EXP The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffe… Patch first 9.8 critical 83.3% 2017-01-30
CVE-2010-3765 KEV EXP Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10… Patch first 9.8 critical 83.2% 2010-10-28
CVE-2015-1187 KEV EXP The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp. Patch first 9.8 critical 82.9% 2017-09-21
CVE-2018-6789 KEV EXP An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may ha… Patch first 9.8 critical 82.1% 2018-02-08
CVE-2018-13382 KEV EXP An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1… Patch first 9.1 critical 81.7% 2019-06-04
CVE-2020-14871 KEV EXP Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 1… Patch first 10.0 critical 80.2% 2020-10-21
CVE-2013-4810 KEV EXP HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attack… Patch first 9.8 critical 79.5% 2013-09-16
CVE-2013-3346 KEV EXP Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of… Patch first 9.8 critical 78.9% 2013-08-30
CVE-2017-11357 KEV EXP Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perf… Patch first 9.8 critical 77.7% 2017-08-23
CVE-2012-0391 KEV EXP The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for… Patch first 9.8 critical 75.6% 2012-01-08
CVE-2017-9248 KEV EXP Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.… Patch first 9.8 critical 75.1% 2017-07-03
CVE-2014-0780 KEV EXP Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative password… Patch first 9.8 critical 74.7% 2014-04-25
CVE-2005-2773 KEV EXP HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node param… Patch first 9.8 critical 74.6% 2005-09-02
CVE-2015-3043 KEV EXP Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to… Patch first 9.8 critical 73.9% 2015-04-14
CVE-2017-6316 KEV EXP Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On… Patch first 9.8 critical 73% 2017-07-20
CVE-2018-7841 KEV EXP A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper se… Patch first 9.8 critical 72.7% 2019-05-22
CVE-2010-4344 KEV EXP Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMT… Patch first 9.8 critical 71.7% 2010-12-14
CVE-2016-2386 KEV EXP SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspeci… Patch first 9.8 critical 71.5% 2016-02-16
CVE-2017-6077 KEV EXP ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metac… Patch first 9.8 critical 68.7% 2017-02-22
CVE-2013-2729 KEV EXP Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code… Patch first 9.8 critical 66.6% 2013-05-16
CVE-2026-0770 KEV EXP Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote a… Patch first 9.8 critical 63.8% 2026-01-23
CVE-2025-32463 KEV EXP Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot op… Patch first 9.3 critical 61% 2025-06-30
CVE-2018-7445 KEV EXP A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the… Patch first 9.8 critical 60.8% 2018-03-19
CVE-2019-11708 KEV EXP Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent p… Patch first 10.0 critical 55.9% 2019-07-23
CVE-2026-39987 KEV EXP marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks aut… Patch first 9.8 critical 37.9% 2026-04-09
CVE-2026-56290 KEV EXP Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable… Patch first 9.8 critical 30.9% 2026-06-29
← previous page 6 of 21 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt