peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,074 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

36,703 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-27151 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP. Patch early 9.8 critical 23% 2021-02-10
CVE-2021-27152 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded awnfibre / fibre@dm!n credentials for an IS… Patch early 9.8 critical 23% 2021-02-10
CVE-2021-27159 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP. Patch early 9.8 critical 23% 2021-02-10
CVE-2021-27163 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / tele1234 credentials for an ISP. Patch early 9.8 critical 23% 2021-02-10
CVE-2019-12928 The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code exec… Patch early 9.8 critical 23% 2019-06-24
CVE-2022-23676 A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; Aruba… Patch early 9.8 critical 23% 2022-05-10
CVE-2024-43917 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows… Patch early 9.3 critical 23% 2024-08-29
CVE-2024-29943 An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerabil… Patch early 9.8 critical 22.9% 2024-03-22
CVE-2023-27076 Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter. Patch early 9.8 critical 22.9% 2023-04-10
CVE-2020-7048 The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the i… Patch early 9.1 critical 22.9% 2020-01-16
CVE-2025-43984 An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211). They are vulnerable… Patch early 9.8 critical 22.9% 2025-08-14
CVE-2022-29009 Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows… Patch early 9.8 critical 22.9% 2022-05-11
CVE-2020-28070 SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via… Patch early 9.8 critical 22.9% 2020-12-23
CVE-2018-13354 System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter. Patch early 9.8 critical 22.9% 2018-11-27
CVE-2024-23625 A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit thi… Patch early 9.6 critical 22.8% 2024-01-26
CVE-2024-37186 An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTT… Patch early 9.1 critical 22.8% 2025-01-14
CVE-2024-29974 ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before … Patch early 9.8 critical 22.8% 2024-06-04
CVE-2016-6808 Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42. Patch early 9.8 critical 22.7% 2017-04-12
CVE-2022-28956 An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload. Patch early 9.8 critical 22.7% 2022-05-18
CVE-2021-39378 A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL… Patch early 9.8 critical 22.7% 2021-09-01
CVE-2025-9501 The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated u… Patch early 9.0 critical 22.6% 2025-11-17
CVE-2023-46042 An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo(). Patch early 9.8 critical 22.6% 2023-10-19
CVE-2022-28557 There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, w… Patch early 9.8 critical 22.6% 2022-05-04
CVE-2017-18371 The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded… Patch early 9.8 critical 22.5% 2019-05-02
CVE-2018-8327 A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This… Patch early 9.8 critical 22.5% 2018-07-11
CVE-2017-14980 Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login. Patch early 9.8 critical 22.5% 2017-10-10
CVE-2022-34555 TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is exploited via a crafted packet… Patch early 9.8 critical 22.5% 2022-07-28
CVE-2022-26272 A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted string written to the file app… Patch early 9.8 critical 22.5% 2022-03-24
CVE-2019-10232 Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php. Patch early 9.8 critical 22.4% 2019-03-27
CVE-2024-47908 OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achie… Patch early 9.1 critical 22.3% 2025-02-11
← previous page 104 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt