peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

36,703 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-8589 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… Patch early 9.8 critical 26.2% 2017-07-11
CVE-2021-24074 Windows TCP/IP Remote Code Execution Vulnerability Patch early 9.8 critical 26.2% 2021-02-25
CVE-2019-6703 Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated… Patch early 9.8 critical 26.1% 2019-01-27
CVE-2023-31719 FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin. Patch early 9.8 critical 26% 2023-09-22
CVE-2024-34359 llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency… Patch early 9.6 critical 26% 2024-05-14
CVE-2024-23624 A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability… Patch early 9.6 critical 26% 2024-01-26
CVE-2022-35555 A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for… Patch early 9.8 critical 26% 2022-08-12
CVE-2023-33831 A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a craf… Patch early 9.8 critical 26% 2023-09-18
CVE-2022-1020 The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_… Patch early 9.8 critical 25.9% 2022-04-18
CVE-2025-27364 In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilat… Patch early 10.0 critical 25.9% 2025-02-24
CVE-2022-37159 Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload. Patch early 9.8 critical 25.9% 2022-08-25
CVE-2022-47071 In NVS365 V01, the background network test function can trigger command execution. Patch early 9.8 critical 25.9% 2023-02-06
CVE-2023-30013 TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerab… Patch early 9.8 critical 25.9% 2023-05-05
CVE-2018-15958 Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data… Patch early 9.8 critical 25.9% 2018-09-25
CVE-2018-15959 Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data… Patch early 9.8 critical 25.9% 2018-09-25
CVE-2018-15965 Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data… Patch early 9.8 critical 25.9% 2018-09-25
CVE-2022-30887 Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.p… Patch early 9.8 critical 25.8% 2022-05-20
CVE-2023-33404 An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows… Patch early 9.8 critical 25.8% 2023-06-26
CVE-2021-21669 Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Patch early 9.8 critical 25.7% 2021-06-18
CVE-2019-7091 ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Succ… Patch early 9.8 critical 25.7% 2019-05-24
CVE-2022-37057 D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main. Patch early 9.8 critical 25.6% 2022-08-28
CVE-2024-9487 An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to b… Patch early 9.1 critical 25.6% 2024-10-10
CVE-2022-26213 Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz para… Patch early 9.8 critical 25.6% 2022-03-15
CVE-2022-39214 Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able t… Patch early 9.6 critical 25.6% 2023-03-14
CVE-2025-6934 The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vuln… Patch early 9.8 critical 25.6% 2025-07-01
CVE-2025-22954 GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid p… Patch early 10.0 critical 25.6% 2025-03-12
CVE-2024-5182 A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion… Patch early 9.1 critical 25.5% 2024-06-20
CVE-2022-32532 Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatche… Patch early 9.8 critical 25.5% 2022-06-29
CVE-2024-6386 The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Inject… Patch early 9.9 critical 25.5% 2024-08-21
CVE-2025-60021 Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to i… Patch early 9.8 critical 25.5% 2026-01-16
← previous page 100 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt